Re: [perpass] US intelligence chief says we might use the IoT to spy on you

Stephen Farrell <stephen.farrell@cs.tcd.ie> Thu, 11 February 2016 15:14 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: perpass@ietfa.amsl.com
Delivered-To: perpass@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5481C1B3335 for <perpass@ietfa.amsl.com>; Thu, 11 Feb 2016 07:14:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.302
X-Spam-Level:
X-Spam-Status: No, score=-4.302 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6zoOKmh4N4-6 for <perpass@ietfa.amsl.com>; Thu, 11 Feb 2016 07:14:41 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 127E81B331D for <perpass@ietf.org>; Thu, 11 Feb 2016 07:14:41 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 64E53BE3E; Thu, 11 Feb 2016 15:14:39 +0000 (GMT)
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1J_3Up9-8FhY; Thu, 11 Feb 2016 15:14:39 +0000 (GMT)
Received: from [134.226.36.93] (bilbo.dsg.cs.tcd.ie [134.226.36.93]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id DB424BE25; Thu, 11 Feb 2016 15:14:38 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1455203679; bh=ZmpNAO9NuKDzFzwlduQAAqaTQAILPlgfglkfErvz14o=; h=Subject:To:References:From:Date:In-Reply-To:From; b=l3Qk+6Wig9kIIBooBcTxu4ZXHbUVyRF4TraxlPjage/EHUpPG8nEf1TWbF6kTmb0r GYQqLc4VWmReF4mZznEuvOe69W53oGiCmAZTGiZmDZtseN7VDGW2kI5om/Vadut7AX vPFKb7eF4LgwkX9wX/6472yN0B80uMAz5BB3WbaE=
To: Russ Housley <housley@vigilsec.com>, perpass <perpass@ietf.org>
References: <D2E1E4F0.3C6A1%harper@isoc.org> <946B2223-C0BD-4AFE-AE76-99478609104F@vigilsec.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Message-ID: <56BCA55E.2020205@cs.tcd.ie>
Date: Thu, 11 Feb 2016 15:14:38 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.5.1
MIME-Version: 1.0
In-Reply-To: <946B2223-C0BD-4AFE-AE76-99478609104F@vigilsec.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-256"; boundary="------------ms050604050302090204090903"
Archived-At: <http://mailarchive.ietf.org/arch/msg/perpass/gF3LvM8aOdxXM4dE0oyq4L9tuas>
Subject: Re: [perpass] US intelligence chief says we might use the IoT to spy on you
X-BeenThere: perpass@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The perpass list is for IETF discussion of pervasive monitoring. " <perpass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perpass>, <mailto:perpass-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/perpass/>
List-Post: <mailto:perpass@ietf.org>
List-Help: <mailto:perpass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perpass>, <mailto:perpass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Feb 2016 15:14:43 -0000


On 11/02/16 15:02, Russ Housley wrote:
> http://www.theguardian.com/technology/2016/feb/09/internet-of-things-smart-home-devices-government-surveillance-james-clapper?CMP=share_btn_fb
>
> 
Yeah, that's a shocker eh;-(

FYI, I did try to argue for defining a padding scheme
in the COSE wg [1] but nobody else seems to care, so at
present, I think they won't define a mechanism.

Padding of course isn't anywhere near sufficient but if
we don't add such mechanisms to our protocols, then ISTM
that we're making that kind of tracking easier.

More broadly, if someone has expertise in this space,
and would like to do a presentation at a saag session
at an IETF meeting, I think that'd be good. Contact
Kathleen and I if so.

S.


[1] https://mailarchive.ietf.org/arch/msg/cose/eq6HMc8tm1sYghpS8LFcvADZPn8


> 
> 
> 
> _______________________________________________ perpass mailing list 
> perpass@ietf.org https://www.ietf.org/mailman/listinfo/perpass
>