Re: [perpass] Fwd: New Version Notification for draft-barnes-pervasive-problem-00.txt
Paul Lambert <paul@marvell.com> Tue, 07 January 2014 21:53 UTC
Return-Path: <paul@marvell.com>
X-Original-To: perpass@ietfa.amsl.com
Delivered-To: perpass@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 231FF1AE207 for <perpass@ietfa.amsl.com>; Tue, 7 Jan 2014 13:53:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.566
X-Spam-Level:
X-Spam-Status: No, score=-1.566 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, IP_NOT_FRIENDLY=0.334, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gVThioLA4See for <perpass@ietfa.amsl.com>; Tue, 7 Jan 2014 13:53:02 -0800 (PST)
Received: from mx0a-0016f401.pphosted.com (mx0a-0016f401.pphosted.com [67.231.148.174]) by ietfa.amsl.com (Postfix) with ESMTP id D21021AE1F5 for <perpass@ietf.org>; Tue, 7 Jan 2014 13:53:02 -0800 (PST)
Received: from pps.filterd (m0045849.ppops.net [127.0.0.1]) by mx0a-0016f401.pphosted.com (8.14.5/8.14.5) with SMTP id s07Lqr3J010680; Tue, 7 Jan 2014 13:52:53 -0800
Received: from sc-owa02.marvell.com ([199.233.58.137]) by mx0a-0016f401.pphosted.com with ESMTP id 1h8877379f-9 (version=TLSv1/SSLv3 cipher=RC4-MD5 bits=128 verify=NOT); Tue, 07 Jan 2014 13:52:53 -0800
Received: from SC-vEXCH2.marvell.com ([10.93.76.134]) by sc-owa02.marvell.com ([10.93.76.22]) with mapi; Tue, 7 Jan 2014 13:52:52 -0800
From: Paul Lambert <paul@marvell.com>
To: Richard Barnes <rlb@ipv.sx>
Date: Tue, 07 Jan 2014 13:52:50 -0800
Thread-Topic: [perpass] Fwd: New Version Notification for draft-barnes-pervasive-problem-00.txt
Thread-Index: Ac8L8tAJZ7zncbfITvq1eHVe6iCP+Q==
Message-ID: <CEF1B205.2BC2A%paul@marvell.com>
References: <20140107021702.7140.81609.idtracker@ietfa.amsl.com> <CAL02cgRsBQNYd2n05548ZbK-ciPkSNJ=U2V0iv+080p9-1gQbA@mail.gmail.com> <7BAC95F5A7E67643AAFB2C31BEE662D018B7D6E1E4@SC-VEXCH2.marvell.com> <CAL02cgT5u1w-MJfxWHZOdiDQRU_Ov_wGYf7=0O-BH_td-Nis8Q@mail.gmail.com>
In-Reply-To: <CAL02cgT5u1w-MJfxWHZOdiDQRU_Ov_wGYf7=0O-BH_td-Nis8Q@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.3.9.131030
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_CEF1B2052BC2Apaulmarvellcom_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2014-01-07_07:2014-01-07, 2014-01-07, 1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 suspectscore=0 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1401070141
Cc: perpass <perpass@ietf.org>
Subject: Re: [perpass] Fwd: New Version Notification for draft-barnes-pervasive-problem-00.txt
X-BeenThere: perpass@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The perpass list is for IETF discussion of pervasive monitoring. " <perpass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perpass>, <mailto:perpass-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/perpass/>
List-Post: <mailto:perpass@ietf.org>
List-Help: <mailto:perpass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perpass>, <mailto:perpass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 07 Jan 2014 21:53:07 -0000
Hi Richard, Minor comment – don’t see any text on L2 wireless tracking. All of our wireless devices effectively beacon our location and identity (e.g 802.11 MAC addresses and probing). While not strictly a IETF domain of work (L2), the solutions to this class of problems do require changes in IETF protocols. I also wonder to what degree this is a "pervasive attack" issue. If the attack involves being physically close to the victim, it's hard to see how the attacker would achieve a pervasive scale. MAC address are readily picked up by any hotspot, mobile device, or by special monitoring devices. Commercial systems already exist to aggregate, track and identify people based on unique identifiers in our radio transmissions. A fun example is the Renew Orb (a trash can that tracks people): http://renewlondon.com/2013/06/renew-release-results-of-smartphone-data-capture/ In one week, 7 trash cans were able to track 530M devices. I’ve seen larger system solutions for sale suitable for country-wide analysis at a security conference in Singapore a few years back … What sorts of changes to IETF protocols are you imagining? Most of the work is IEEE related. Impacts to IETF protocols might include: - IP address assignment and IPv6 usage of MAC address - authentication protocols/framework to bind ephemeral MAC address to longer term identity - RADIUS/EAP usage changes Paul --Richard Paul From: perpass [mailto:perpass-bounces@ietf.org<mailto:perpass-bounces@ietf.org>] On Behalf Of Richard Barnes Sent: Monday, January 06, 2014 6:24 PM To: perpass Subject: [perpass] Fwd: New Version Notification for draft-barnes-pervasive-problem-00.txt Dear PERPASS, Stephen asked me to take a stab at a problem statement for PERPASS. With some help from Bruce, Cullen, and Ted, the results have just been published as draft-barnes-pervasive-problem-00. In general, this draft tries to outline at a technical level what we mean by pervasive attack, and what the high level mitigations are. Comments welcome! Thanks, --Richard ---------- Forwarded message ---------- From: <internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>> Date: Mon, Jan 6, 2014 at 9:17 PM Subject: New Version Notification for draft-barnes-pervasive-problem-00.txt To: Cullen Jennings <fluffy@cisco.com<mailto:fluffy@cisco.com>>, Ted Hardie <ted.ietf@gmail.com<mailto:ted.ietf@gmail.com>>, Bruce Schneier <schneier@schneier.com<mailto:schneier@schneier.com>>, Richard Barnes <rlb@ipv.sx<mailto:rlb@ipv.sx>> A new version of I-D, draft-barnes-pervasive-problem-00.txt has been successfully submitted by Richard Barnes and posted to the IETF repository. Name: draft-barnes-pervasive-problem Revision: 00 Title: Pervasive Attack: A Threat Model and Problem Statement Document date: 2014-01-06 Group: Individual Submission Pages: 23 URL: http://www.ietf.org/internet-drafts/draft-barnes-pervasive-problem-00.txt Status: https://datatracker.ietf.org/doc/draft-barnes-pervasive-problem/ Htmlized: http://tools.ietf.org/html/draft-barnes-pervasive-problem-00 Abstract: Documents published in 2013 have revealed several classes of "pervasive" attack on Internet communications. In this document, we review the main attacks that have been published, and develop a threat model that describes these pervasive attacks. Based on this threat model, we discuss the techniques that can be employed in Internet protocol design to increase the protocols robustness to pervasive attacks. Please note that it may take a couple of minutes from the time of submission until the htmlized version and diff are available at tools.ietf.org<http://tools.ietf.org>. The IETF Secretariat
- [perpass] Fwd: New Version Notification for draft… Richard Barnes
- Re: [perpass] Fwd: New Version Notification for d… Paul Lambert
- Re: [perpass] Fwd: New Version Notification for d… Richard Barnes
- Re: [perpass] Fwd: New Version Notification for d… Watson Ladd
- Re: [perpass] Fwd: New Version Notification for d… Richard Barnes
- Re: [perpass] Fwd: New Version Notification for d… Linus Nordberg
- Re: [perpass] Fwd: New Version Notification for d… Stephen Farrell
- Re: [perpass] Fwd: New Version Notification for d… Eliot Lear
- Re: [perpass] Fwd: New Version Notification for d… Paul Lambert
- Re: [perpass] Fwd: New Version Notification for d… Paul Lambert
- Re: [perpass] Fwd: New Version Notification for d… Stefan Winter
- Re: [perpass] Fwd: New Version Notification for d… Eliot Lear
- Re: [perpass] New Version Notification for draft-… Sean Turner
- Re: [perpass] Fwd: New Version Notification for d… Stephen Farrell
- Re: [perpass] Fwd: New Version Notification for d… joel jaeggli
- Re: [perpass] Fwd: New Version Notification for d… Martin Thomson
- Re: [perpass] Fwd: New Version Notification for d… Stefan Winter