Re: [perpass] Lauren Weinstein on Explicit Trusted Proxy in HTTP/2.0: "One of the Most Alarming Internet Proposals I've Ever Seen"

Stephen Farrell <stephen.farrell@cs.tcd.ie> Mon, 24 February 2014 15:33 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: perpass@ietfa.amsl.com
Delivered-To: perpass@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 60D691A0127 for <perpass@ietfa.amsl.com>; Mon, 24 Feb 2014 07:33:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.548
X-Spam-Level:
X-Spam-Status: No, score=-0.548 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, RP_MATCHES_RCVD=-0.547] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BVN2EAaa_3vN for <perpass@ietfa.amsl.com>; Mon, 24 Feb 2014 07:33:04 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) by ietfa.amsl.com (Postfix) with ESMTP id 104F31A0126 for <perpass@ietf.org>; Mon, 24 Feb 2014 07:33:03 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 4D22ABEFD; Mon, 24 Feb 2014 15:33:02 +0000 (GMT)
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dFEEHIYevasp; Mon, 24 Feb 2014 15:33:02 +0000 (GMT)
Received: from [134.226.36.180] (stephen-think.dsg.cs.tcd.ie [134.226.36.180]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id 1F1B9BEEC; Mon, 24 Feb 2014 15:33:02 +0000 (GMT)
Message-ID: <530B662E.3070708@cs.tcd.ie>
Date: Mon, 24 Feb 2014 15:33:02 +0000
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.3.0
MIME-Version: 1.0
To: Andreas Kuckartz <a.kuckartz@ping.de>, perpass <perpass@ietf.org>
References: <530B637E.4020308@ping.de>
In-Reply-To: <530B637E.4020308@ping.de>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/perpass/SQhtIL1cEZiHCPaKzPXTEHUFl20
Subject: Re: [perpass] Lauren Weinstein on Explicit Trusted Proxy in HTTP/2.0: "One of the Most Alarming Internet Proposals I've Ever Seen"
X-BeenThere: perpass@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The perpass list is for IETF discussion of pervasive monitoring. " <perpass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perpass>, <mailto:perpass-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/perpass/>
List-Post: <mailto:perpass@ietf.org>
List-Help: <mailto:perpass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perpass>, <mailto:perpass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 24 Feb 2014 15:33:07 -0000

Hi Andreas,

On 02/24/2014 03:21 PM, Andreas Kuckartz wrote:
> No, I Don't Trust You! -- One of the Most Alarming Internet Proposals
> I've Ever Seen
> http://lauren.vortex.com/archive/001076.html

Yes. That's a bit OTT IMO and unfortunately liable to mislead as
to IETF process if not read very carefully.

> The name of that HTTPBis Working Group draft already sounds suspicious:
> 
> Explicit Trusted Proxy in HTTP/2.0
> draft-loreto-httpbis-trusted-proxy20-01
> http://tools.ietf.org/html/draft-loreto-httpbis-trusted-proxy20-01

That is NOT an httpbis working group draft.

Anyone can write an I-D, that is an input to a working group
saying what the authors think. The topic of proxies is a
valid one for HTTP and is being discussed on the WG list.
The above is one input. Other inputs were mails poking holes
in this one. Yet others had other points to make.

> I do not know the details of the processes of the IETF:
> What can I do to help kill that proposal?

If you are interested in HTTP, then subscribe to the WG list,
check the archives to see if what you want to say has been
said (please!) and then contribute like anyone else. Details
for the httpbis WG are at [1].

Cheers,
S.

[1] https://tools.ietf.org/wg/httpbis/

> 
> Cheers,
> Andreas
> 
> _______________________________________________
> perpass mailing list
> perpass@ietf.org
> https://www.ietf.org/mailman/listinfo/perpass
> 
>