Re: [perpass] US intelligence chief says we might use the IoT to spy on you

Dave Crocker <dhc@dcrocker.net> Thu, 11 February 2016 18:49 UTC

Return-Path: <dhc@dcrocker.net>
X-Original-To: perpass@ietfa.amsl.com
Delivered-To: perpass@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F0A781B3915 for <perpass@ietfa.amsl.com>; Thu, 11 Feb 2016 10:49:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4eGXe7wFXEs2 for <perpass@ietfa.amsl.com>; Thu, 11 Feb 2016 10:49:43 -0800 (PST)
Received: from sbh17.songbird.com (sbh17.songbird.com [72.52.113.17]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E8E981B3914 for <perpass@ietf.org>; Thu, 11 Feb 2016 10:49:42 -0800 (PST)
Received: from [192.168.1.87] (76-218-10-206.lightspeed.sntcca.sbcglobal.net [76.218.10.206]) (authenticated bits=0) by sbh17.songbird.com (8.13.8/8.13.8) with ESMTP id u1BInTSd032640 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NOT); Thu, 11 Feb 2016 10:49:30 -0800
To: Christian Huitema <huitema@huitema.net>, 'Stephen Farrell' <stephen.farrell@cs.tcd.ie>, 'Russ Housley' <housley@vigilsec.com>, 'perpass' <perpass@ietf.org>
References: <D2E1E4F0.3C6A1%harper@isoc.org> <946B2223-C0BD-4AFE-AE76-99478609104F@vigilsec.com> <56BCA55E.2020205@cs.tcd.ie> <0cbc01d164fb$88b09da0$9a11d8e0$@huitema.net>
From: Dave Crocker <dhc@dcrocker.net>
Organization: Brandenburg InternetWorking
Message-ID: <56BCD7B9.9070902@dcrocker.net>
Date: Thu, 11 Feb 2016 10:49:29 -0800
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:38.0) Gecko/20100101 Thunderbird/38.5.1
MIME-Version: 1.0
In-Reply-To: <0cbc01d164fb$88b09da0$9a11d8e0$@huitema.net>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.0 (sbh17.songbird.com [72.52.113.17]); Thu, 11 Feb 2016 10:49:30 -0800 (PST)
Archived-At: <http://mailarchive.ietf.org/arch/msg/perpass/sId1U0H27eTy-rJ2T2XV5Ei0zbA>
Subject: Re: [perpass] US intelligence chief says we might use the IoT to spy on you
X-BeenThere: perpass@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: dcrocker@bbiw.net
List-Id: "The perpass list is for IETF discussion of pervasive monitoring. " <perpass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perpass>, <mailto:perpass-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/perpass/>
List-Post: <mailto:perpass@ietf.org>
List-Help: <mailto:perpass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perpass>, <mailto:perpass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Feb 2016 18:49:45 -0000


On 2/11/2016 10:39 AM, Christian Huitema wrote:
> any of the appliances are designed to "report to the cloud," and have
> a business model based on the "big data" that they acquire. If we
> design appliances like that, it will be hard to keep "big brother"
> away.
...
> Sure, encrypting the communications between the appliances and the
> cloud cannot hurt. But we should also look at standardization, so
> that appliances can communicate directly, or so that people could
> easily switch the "appliance monitoring" services. In the absence of
> such standards, we get lots of info concentrated in few places, which
> becomes of course a target for all kind of spying.


Yes, but...

First, tablets and, now, PCs are following exactly the same reporting model.

Second, the 'monitoring' is controlled by the original vendor and they 
have no interest in handing that control over to anyone else, no is 
there any groundswell among customers to force the change.

Standards work when there is a very strong market force demanding them. 
  We ain't got that.  Yet(?)

d/
-- 
Dave Crocker
Brandenburg InternetWorking
bbiw.net