Re: [Privacy-pass] The PRIVACYPASS WG has placed draft-wood-privacypass-auth-scheme-extensions in state "Call For Adoption By WG Issued"
Thibault Meunier <ot-ietf@thibault.uk> Mon, 19 February 2024 17:10 UTC
Return-Path: <ot-ietf@thibault.uk>
X-Original-To: privacy-pass@ietfa.amsl.com
Delivered-To: privacy-pass@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4CB81C14F73E for <privacy-pass@ietfa.amsl.com>; Mon, 19 Feb 2024 09:10:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.105
X-Spam-Level:
X-Spam-Status: No, score=-2.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thibault.uk
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BoXo1BMsKJSN for <privacy-pass@ietfa.amsl.com>; Mon, 19 Feb 2024 09:10:34 -0800 (PST)
Received: from mail-40136.proton.ch (mail-40136.proton.ch [185.70.40.136]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CC794C14F5F2 for <privacy-pass@ietf.org>; Mon, 19 Feb 2024 09:10:33 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thibault.uk; s=protonmail; t=1708362631; x=1708621831; bh=mo/EXjRrRVitWidtiGYXRC2oPy6ptZmz+fkj+jGANZo=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=FGnspqLtSQVcLd5QnWHfxY9hSE/xQAcf4E2En5DgPHnB926btKg5YnlA1fL0m3yrx +s8Sb5JO+z2iNuiWwwe9DVJr+3ThGs2QrwhDBpwNuCoTEQz6N+7IlJJx5HIOylRJ+G JP1RvYw9B997yXWWccaTaZe9VoATC1VjBQtgK8QM=
Date: Mon, 19 Feb 2024 17:10:12 +0000
To: Tommy Pauly <tpauly=40apple.com@dmarc.ietf.org>
From: Thibault Meunier <ot-ietf@thibault.uk>
Cc: Ben Schwartz <bemasc=40meta.com@dmarc.ietf.org>, "privacy-pass@ietf.org" <privacy-pass@ietf.org>
Message-ID: <V0hOXeWZP7Z3xxD5m4oK4ROqOtCUSG9JyxkMcpSwhrLLTxyEN-ZdfP1rC-ER87due5C6zv47H-wkPkowuvk-lEQJk53mfl57rKiHoggSI9c=@thibault.uk>
In-Reply-To: <F235DBE1-19B7-4738-BCEF-D2E4911206BD@apple.com>
References: <170664197290.48538.11458873071334659518@ietfa.amsl.com> <SA1PR15MB437035BCB976667A27F13212B37D2@SA1PR15MB4370.namprd15.prod.outlook.com> <SA1PR15MB4370AC2E72FD41FA8277F9DFB37D2@SA1PR15MB4370.namprd15.prod.outlook.com> <F235DBE1-19B7-4738-BCEF-D2E4911206BD@apple.com>
Feedback-ID: 60844204:user:proton
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="b1_cONgmjfSaSdrfOApSKlFE75Zx3SnTnRVHVN2sUGmAY"
Archived-At: <https://mailarchive.ietf.org/arch/msg/privacy-pass/Yg5xdnceQq5QCQOp_b4vpDvMDYk>
Subject: Re: [Privacy-pass] The PRIVACYPASS WG has placed draft-wood-privacypass-auth-scheme-extensions in state "Call For Adoption By WG Issued"
X-BeenThere: privacy-pass@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Privacy Pass Protocol <privacy-pass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/privacy-pass>, <mailto:privacy-pass-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/privacy-pass/>
List-Post: <mailto:privacy-pass@ietf.org>
List-Help: <mailto:privacy-pass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/privacy-pass>, <mailto:privacy-pass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Feb 2024 17:10:38 -0000
I'm currently going over the two documents (and the associated cfrg draft) about Privacy Pass with metadata. During the review, I've found these additional documents helpful: - Two possible extensions for the registry created in draft-wood-privacypass-auth-scheme-extension: [geo-extension](https://datatracker.ietf.org/doc/draft-hendrickson-privacypass-geo-extension/), [expiration-extension](https://datatracker.ietf.org/doc/draft-hendrickson-privacypass-expiration-extension/01/) - Partially Blind RSA draft at CFRG: [draft-amjad-cfrg-partially-blind-rsa-02.html](https://www.ietf.org/archive/id/draft-amjad-cfrg-partially-blind-rsa-02.html) Best, Thibault On Monday, 19 February 2024 at 17:56, Tommy Pauly <tpauly=40apple.com@dmarc.ietf.org> wrote: > The core privacy pass architecture talks about metadata-supporting token types, so overall I think the WG needs to say something in this space. > > Looking at the two documents here: > > - draft-wood-privacypass-auth-scheme-extensions is a very minimal and reasonable mechanism. Assuming that we have drafts (like the other one) that will use it, I support adopting this document as the starting place for allowing the auth scheme to support extensions. > > - draft-hendrickson-privacypass-public-metadata, for an approach to adding metadata, also seems like a nice minimal approach. In general, I’m still concerned about metadata and the implication on privacy analysis. I think the document will need to say a lot more on what kind of metadata would be safe, how to guarantee consistency, and how to not allow the metadata to become a way to identify a single client across the issuance and redemption contexts. For example, if the metadata item is something that the client already is sharing with both the issuance and redemption contexts, and knows will be visible to everyone already, then adding the metadata doesn’t leak any additional state. However, if this is not the case, then it may be risky to reveal information to the issuance path that would otherwise not be visible. Providing some very concrete examples of what metadata can be would help immensely in the discussion. > > So, for this one, I am provisionally supportive of adoption if we can better articulate the bounds on usage and some clear cases that we can agree are admissible. > > As a nit on draft-hendrickson-privacypass-public-metadata: it uses the Blind(), BlindSign(), and Finalize() functions from RSA Blinding with extra parameters for the extensions that aren’t defined in the main RSA Blinding spec. Are these concatenations, or just cases of running the functions twice? > > Thanks, > Tommy > >> On Jan 30, 2024, at 11:28 AM, Ben Schwartz <bemasc=40meta.com@dmarc.ietf.org> wrote: >> >> -extra aliases. >> >> --------------------------------------------------------------- >> >> From:Ben Schwartz <bemasc@meta.com> >> Sent:Tuesday, January 30, 2024 2:21 PM >> To:IETF Secretariat <ietf-secretariat-reply@ietf.org>; draft-wood-privacypass-auth-scheme-extensions@ietf.org <draft-wood-privacypass-auth-scheme-extensions@ietf.org>; privacy-pass@ietf.org <privacy-pass@ietf.org>; privacypass-chairs@ietf.org <privacypass-chairs@ietf.org> >> Subject:Re: [Privacy-pass] The PRIVACYPASS WG has placed draft-wood-privacypass-auth-scheme-extensions in state "Call For Adoption By WG Issued" >> >> Hi PRIVACYPASS, >> >> draft-hendrickson-privacypass-public-metadata and >> draft-wood-privacypass-auth-scheme-extensions have a mutual normative dependency, so (as previously discussed) the chairs have put them forward for a joint adoption call. We hope that 3 weeks will be enough time for everyone to read both drafts and comment on their suitability for adoption. >> >> If you support or oppose adoption, please comment in this thread. >> >> --Ben Schwartz >> >> --------------------------------------------------------------- >> >> From:Privacy-pass <privacy-pass-bounces@ietf.org> on behalf of IETF Secretariat <ietf-secretariat-reply@ietf.org> >> Sent:Tuesday, January 30, 2024 2:12 PM >> To:draft-wood-privacypass-auth-scheme-extensions@ietf.org <draft-wood-privacypass-auth-scheme-extensions@ietf.org>; privacy-pass@ietf.org <privacy-pass@ietf.org>; privacypass-chairs@ietf.org <privacypass-chairs@ietf.org> >> Subject:[Privacy-pass] The PRIVACYPASS WG has placed draft-wood-privacypass-auth-scheme-extensions in state "Call For Adoption By WG Issued" >> >> !-------------------------------------------------------------------| >> This Message Is From an External Sender >> >> |-------------------------------------------------------------------! >> >> The PRIVACYPASS WG has placed draft-wood-privacypass-auth-scheme-extensions >> in state Call For Adoption By WG Issued (entered by Benjamin Schwartz) >> >> The document is available at >> https://datatracker.ietf.org/doc/draft-wood-privacypass-auth-scheme-extensions/ >> >> Comment: >> Joint adoption call for draft-hendrickson-privacypass-public-metadata and >> draft-wood-privacypass-auth-scheme-extensions. >> >> -- >> Privacy-pass mailing list >> Privacy-pass@ietf.org >> https://www.ietf.org/mailman/listinfo/privacy-pass-- >> Privacy-pass mailing list >> Privacy-pass@ietf.org >> https://www.ietf.org/mailman/listinfo/privacy-pass
- [Privacy-pass] The PRIVACYPASS WG has placed draf… IETF Secretariat
- Re: [Privacy-pass] The PRIVACYPASS WG has placed … Ben Schwartz
- Re: [Privacy-pass] The PRIVACYPASS WG has placed … Ben Schwartz
- Re: [Privacy-pass] The PRIVACYPASS WG has placed … Tommy Pauly
- Re: [Privacy-pass] The PRIVACYPASS WG has placed … Thibault Meunier
- Re: [Privacy-pass] The PRIVACYPASS WG has placed … Steven Valdez
- Re: [Privacy-pass] The PRIVACYPASS WG has placed … David Schinazi
- Re: [Privacy-pass] The PRIVACYPASS WG has placed … Aykut Bulut
- Re: [Privacy-pass] The PRIVACYPASS WG has placed … Eli-Shaoul Khedouri
- Re: [Privacy-pass] The PRIVACYPASS WG has placed … Thibault Meunier