Re: [radext] CUI comments in "deprecating insecure transports"
Alan DeKok <aland@deployingradius.com> Wed, 26 July 2023 15:16 UTC
Return-Path: <aland@deployingradius.com>
X-Original-To: radext@ietfa.amsl.com
Delivered-To: radext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6A71FC151534 for <radext@ietfa.amsl.com>; Wed, 26 Jul 2023 08:16:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.909
X-Spam-Level:
X-Spam-Status: No, score=-1.909 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rZZumrDzcgpm for <radext@ietfa.amsl.com>; Wed, 26 Jul 2023 08:16:49 -0700 (PDT)
Received: from mail.networkradius.com (mail.networkradius.com [62.210.147.122]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DA1F1C1516EA for <radext@ietf.org>; Wed, 26 Jul 2023 08:16:48 -0700 (PDT)
Received: from smtpclient.apple (dhcp-93d1.meeting.ietf.org [31.133.147.209]) by mail.networkradius.com (Postfix) with ESMTPSA id 25B9F29F; Wed, 26 Jul 2023 15:16:44 +0000 (UTC)
Authentication-Results: NetworkRADIUS; dmarc=none (p=none dis=none) header.from=deployingradius.com
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.120.41.1.1\))
From: Alan DeKok <aland@deployingradius.com>
In-Reply-To: <06c301d9bfc0$e07154d0$a153fe70$@gmail.com>
Date: Wed, 26 Jul 2023 08:16:43 -0700
Cc: radext@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <5F5C2E17-2061-4FFC-942A-9C4ED861EE5F@deployingradius.com>
References: <BC530A34-D348-44D0-886E-DB1ECF3A5010@deployingradius.com> <06c301d9bfc0$e07154d0$a153fe70$@gmail.com>
To: josh.howlett@gmail.com
X-Mailer: Apple Mail (2.3696.120.41.1.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/radext/S2Qzl95bd5K-7eHMTfUGoFrcRxs>
Subject: Re: [radext] CUI comments in "deprecating insecure transports"
X-BeenThere: radext@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/radext>, <mailto:radext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/radext/>
List-Post: <mailto:radext@ietf.org>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/radext>, <mailto:radext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Jul 2023 15:16:51 -0000
On Jul 26, 2023, at 5:58 AM, <josh.howlett@gmail.com> <josh.howlett@gmail.com> wrote: > > There are good reasons for the CUI value to be persistent, provided that it > is targeted to each network access provider. In this way, different > providers cannot collude to track users. However, they still maintain the > ability to *recognise* (but not identify) the same user that they saw > previously. > > There are legitimate reasons to track and, if necessary, identify users, > including troubleshooting and prevention of service abuse. The intent of CUI was that if a user was abusive, the visited network could report the CUI to the IdP. The IdP would then block the user. While this isn't perfect, it provides for better user privacy. Where there is a trade-off around user privacy, I would lean towards keeping user privacy at the cost of increased effort in the network. I'll see if I can update the wording to suggest that the CUI can be static for one visited / home network relationship, provided they both agree to this. But generally it's better to have it different for every session. The issue of CUI changing is made a little less relevant by the fact that the MAC address doesn't change for one visited network (SSID, etc). So the visited network can always correlate MACs across sessions. But for me, this is about nibbling away at the privacy bits one problem at a time. At some point, MADINAS will perhaps allow MACs to be changed per session, and then that problem will go away. And the CUI will already be different per session (usually). So we won't have to go back and fix it again. Alan DeKok.
- [radext] CUI comments in "deprecating insecure tr… Alan DeKok
- Re: [radext] CUI comments in "deprecating insecur… josh.howlett
- Re: [radext] CUI comments in "deprecating insecur… Alan DeKok
- Re: [radext] CUI comments in "deprecating insecur… Mark Grayson (mgrayson)
- Re: [radext] CUI comments in "deprecating insecur… Alexander Clouter
- Re: [radext] CUI comments in "deprecating insecur… Alan DeKok
- Re: [radext] CUI comments in "deprecating insecur… Alan DeKok
- Re: [radext] CUI comments in "deprecating insecur… Margaret Cullen
- Re: [radext] CUI comments in "deprecating insecur… Alan DeKok
- Re: [radext] CUI comments in "deprecating insecur… Alan DeKok
- Re: [radext] CUI comments in "deprecating insecur… josh.howlett
- Re: [radext] CUI comments in "deprecating insecur… Margaret Cullen
- Re: [radext] CUI comments in "deprecating insecur… josh.howlett
- Re: [radext] CUI comments in "deprecating insecur… Arran Cudbard-Bell
- Re: [radext] CUI comments in "deprecating insecur… Alexander Clouter
- Re: [radext] CUI comments in "deprecating insecur… Alexander Clouter
- Re: [radext] CUI comments in "deprecating insecur… Alexander Clouter
- Re: [radext] CUI comments in "deprecating insecur… Arran Cudbard-Bell
- Re: [radext] CUI comments in "deprecating insecur… Arran Cudbard-Bell
- Re: [radext] CUI comments in "deprecating insecur… Alan DeKok
- Re: [radext] CUI comments in "deprecating insecur… josh.howlett
- Re: [radext] CUI comments in "deprecating insecur… Heikki Vatiainen
- Re: [radext] CUI comments in "deprecating insecur… Heikki Vatiainen
- Re: [radext] CUI comments in "deprecating insecur… Michael Richardson