Re: [perpass] A reminder, the Network is the Enemy...
Phillip Hallam-Baker <hallam@gmail.com> Thu, 05 December 2013 15:27 UTC
Return-Path: <hallam@gmail.com>
X-Original-To: perpass@ietfa.amsl.com
Delivered-To: perpass@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3F9CC1AE030 for <perpass@ietfa.amsl.com>; Thu, 5 Dec 2013 07:27:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IhoDQ0YSVn3J for <perpass@ietfa.amsl.com>; Thu, 5 Dec 2013 07:27:33 -0800 (PST)
Received: from mail-we0-x235.google.com (mail-we0-x235.google.com [IPv6:2a00:1450:400c:c03::235]) by ietfa.amsl.com (Postfix) with ESMTP id 1B0581ADF30 for <perpass@ietf.org>; Thu, 5 Dec 2013 07:27:32 -0800 (PST)
Received: by mail-we0-f181.google.com with SMTP id x55so16989965wes.12 for <perpass@ietf.org>; Thu, 05 Dec 2013 07:27:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=6zcAgsNGBACzmqL3/I0/nk7L94F5CycpawNzXVNz4Ps=; b=NLtlskw2IqI7//Thjr52AoCUKjoLPJJayA0bU0FB5AlKC08QRvk0ZZIbCQ8ECFDrwk BXI73uc5nh2UjTndQEymr6rB2OSupqsuptsxnLXOb7BchNdzoRvGtGJ25Fx3NGPcZfL5 k9v9uPsf2fCKKkdQo/2aQIGzc+DszGxHEOz4wt+PvTpI3PEVBv0ZAP/ctcBrlmUJVFS8 FZOZPyIE0fSdVXHf9EQtlbSIFm5dTcB14etZbwOR8qyK3CuZkFagdTaeXzNjsbQREyU+ y7q72vR8Mi4e5hL9TNHcfdCXekWAIqQFTJXG9tWfge1FzjY83gG8sFeISyEkd/1ZVJfp Dikw==
MIME-Version: 1.0
X-Received: by 10.180.189.80 with SMTP id gg16mr12560784wic.32.1386257249300; Thu, 05 Dec 2013 07:27:29 -0800 (PST)
Received: by 10.194.243.136 with HTTP; Thu, 5 Dec 2013 07:27:29 -0800 (PST)
In-Reply-To: <m2y53z1g2r.wl%randy@psg.com>
References: <C0D19C51-6EA6-4EAF-B9CB-D80F673262E5@icsi.berkeley.edu> <52A050E7.8010405@uni-due.de> <m2y53z1g2r.wl%randy@psg.com>
Date: Thu, 05 Dec 2013 10:27:29 -0500
Message-ID: <CAMm+LwgJU9DSyrOCi0h7WfV4m4ULAAXqnQt9=PUaonTtvU5mzw@mail.gmail.com>
From: Phillip Hallam-Baker <hallam@gmail.com>
To: Randy Bush <randy@psg.com>
Content-Type: multipart/alternative; boundary="001a11c22314e976fa04eccb2aa9"
Cc: perpass <perpass@ietf.org>, Matthäus Wander <matthaeus.wander@uni-due.de>
Subject: Re: [perpass] A reminder, the Network is the Enemy...
X-BeenThere: perpass@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The perpass list is for IETF discussion of pervasive monitoring. " <perpass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perpass>, <mailto:perpass-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/perpass/>
List-Post: <mailto:perpass@ietf.org>
List-Help: <mailto:perpass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perpass>, <mailto:perpass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 05 Dec 2013 15:27:36 -0000
On Thu, Dec 5, 2013 at 10:18 AM, Randy Bush <randy@psg.com> wrote: > > If we assume the attacker can get the private root KSK from an US-based > > corp, then we should also assume they can get the private root ZSK from > > another US-based corp. As the owner of the root ZSK also owns the keys > > for .com, the attack becomes much easier. > > let's start a list of juristictions which we believe are NOT compromised > and dangerous. i will start it off by submitting andorra. > Finding the one person you can trust is a bad strategy. Andorra is considerably less likely to stand up to NSA bullying attempts than Microsoft is. Microsoft certainly has more lawyers. A better approach is to design the system so that it takes a defection by more than one party. Instead of relying on just the ICANN root KSK require a TLD to be signed by three out of five trusted national cryptolabs. -- Website: http://hallambaker.com/
- [perpass] A reminder, the Network is the Enemy... Nicholas Weaver
- Re: [perpass] A reminder, the Network is the Enem… Ted Lemon
- Re: [perpass] A reminder, the Network is the Enem… Bjoern Hoehrmann
- Re: [perpass] A reminder, the Network is the Enem… Ted Lemon
- Re: [perpass] A reminder, the Network is the Enem… Bjoern Hoehrmann
- Re: [perpass] A reminder, the Network is the Enem… Ted Lemon
- Re: [perpass] A reminder, the Network is the Enem… Stephane Bortzmeyer
- Re: [perpass] A reminder, the Network is the Enem… Stephane Bortzmeyer
- Re: [perpass] A reminder, the Network is the Enem… Nicholas Weaver
- Re: [perpass] A reminder, the Network is the Enem… David Conrad
- Re: [perpass] A reminder, the Network is the Enem… Matthäus Wander
- Re: [perpass] A reminder, the Network is the Enem… Randy Bush
- Re: [perpass] A reminder, the Network is the Enem… Phillip Hallam-Baker
- Re: [perpass] A reminder, the Network is the Enem… David Conrad
- Re: [perpass] A reminder, the Network is the Enem… Phillip Hallam-Baker
- Re: [perpass] A reminder, the Network is the Enem… Russ Mundy
- Re: [perpass] A reminder, the Network is the Enem… Phillip Hallam-Baker
- Re: [perpass] A reminder, the Network is the Enem… Stephane Bortzmeyer