[Rats] Removal of the "replay protection and privacy" section in the EAT draft

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Thu, 29 September 2022 11:37 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E8011C14CE47 for <rats@ietfa.amsl.com>; Thu, 29 Sep 2022 04:37:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.909
X-Spam-Level:
X-Spam-Status: No, score=-1.909 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=c6sYP4Te; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=c6sYP4Te
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3APbRAfrYNqp for <rats@ietfa.amsl.com>; Thu, 29 Sep 2022 04:37:29 -0700 (PDT)
Received: from EUR04-VI1-obe.outbound.protection.outlook.com (mail-eopbgr80040.outbound.protection.outlook.com [40.107.8.40]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C8946C1522AE for <rats@ietf.org>; Thu, 29 Sep 2022 04:37:28 -0700 (PDT)
ARC-Seal: i=2; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=pass; b=TZIabsdms4MC9zQzdrmwyrI/yZ6h68RvwuVp0/aCVKyYAPJxb9qdroUx2hx0BGcPepVSRu+s52F6y/T1wzs/By++YrLrIPGPVj7/IhCOLWSnZEU2y6lNq9/aHyIKkIAaIMp1rfO9k0FVpb77kziegK+lxxXABA7HNH4PEUdKEDM+CAlM+LnJu06ktcf+E9swzTG6dP34Gp0wvpVypWiYlLbibde7qRqn+FXtMKFif8G5yvysBEJsNKSe91H3ncCVD9Fr6aVw9/L+fHqfW42Qm9Npsoi4r70/NzF5ixrBGBeLCCXGfiSqmoy6d+4/qJxKbzxE8XtjI3wcD1DqXSbuNA==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=tssdTwwQvV9wrQCvz0dTd4C43942dqahQ9vJD9j/Ulg=; b=NWg2ok0DS5POfUQLfkpDh3PBp3zU0D+Xu9UgdtX54oPVXnHEHug1xXa11IW53X+4SFDImeWKRJNCKLge8L8B1K+ckZXgZgKSV0lW8MoO7ooEk2ulJYasS4FLmvVshQ41j1CFMyOHIFz9kUAIFxdqW+F84LPeEj5rr03Ue1yh5xW7yxNjCKoG4/RbcKYqD1jCDycAnDQe/4B75UYZGu3KSQ+eglyaVcLUEPPKFNeHKUo+cNvwGFJtuW3inydyUSlef54sip/NHNZvl6FrNiTj+grefUzuKDjhW/qibw6spk4sxB/Osf7+GyTUQRaa+TIlGXcSp+wucbX9DsnzIICdzA==
ARC-Authentication-Results: i=2; mx.microsoft.com 1; spf=pass (sender ip is 63.35.35.123) smtp.rcpttodomain=ietf.org smtp.mailfrom=arm.com; dmarc=pass (p=none sp=none pct=100) action=none header.from=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com; arc=pass (0 oda=1 ltdi=1 spf=[1,1,smtp.mailfrom=arm.com] dkim=[1,1,header.d=arm.com] dmarc=[1,1,header.from=arm.com])
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=tssdTwwQvV9wrQCvz0dTd4C43942dqahQ9vJD9j/Ulg=; b=c6sYP4TeNgROMIhRrxQHgrXfRIzUdI8h+3Ci7wn7OroWoik34JWX+UrW8ALG5yazvD870gv3IY9UbXEVMjcJFH0deY5E1pLfKIla38kH2ZIw9R9vRokEHZs27EVLVg7toaPU1zh5klR3Ap6jow/v2Ont8G3U9rJPUTDjDWUgQMM=
Received: from AM5PR0202CA0006.eurprd02.prod.outlook.com (2603:10a6:203:69::16) by DU0PR08MB7740.eurprd08.prod.outlook.com (2603:10a6:10:3bc::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5676.19; Thu, 29 Sep 2022 11:37:24 +0000
Received: from AM7EUR03FT007.eop-EUR03.prod.protection.outlook.com (2603:10a6:203:69:cafe::70) by AM5PR0202CA0006.outlook.office365.com (2603:10a6:203:69::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5676.20 via Frontend Transport; Thu, 29 Sep 2022 11:37:24 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com; pr=C
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM7EUR03FT007.mail.protection.outlook.com (100.127.140.242) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5676.17 via Frontend Transport; Thu, 29 Sep 2022 11:37:22 +0000
Received: ("Tessian outbound d354c7aef2bc:v128"); Thu, 29 Sep 2022 11:37:22 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: 968903947e913266
X-CR-MTA-TID: 64aa7808
Received: from bfabe7e035f2.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 2A8CAC9F-5284-4C64-999C-7D0893C3778A.1; Thu, 29 Sep 2022 11:37:15 +0000
Received: from EUR05-AM6-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id bfabe7e035f2.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Thu, 29 Sep 2022 11:37:15 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=E9VXOjUGPBrzlyk+fz0xD3cSmPeIu9pcVGLgwOOoARw86nVOLrmCbTavkAVQsRKbD7Gu3AxIsOKGsiO1ZdfGFovmVQyQ8Tv+vCcviNVB7yRS8ei3sn5JMRX+Oyk4zPmTA2vLsASjqvGT9kfAwgSEZTy5u1HUzjf///nv1qVpUxC7KT9WwiArYRpv+8WitlOIXsSmb5PKJQ6KNU1rUOaybmZYM6dP9XfGKBDDNbikkNrpnzW9m+C4p3+IBZiveAMfVaLVoMKIAL6q9eXOZiZZ3etQ94WUL/Qb+j5GzD8Gvzo/MHNLE8fT8VbaaV8edHHqTL4JXd4ryBhhUjfhNn3rcg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=tssdTwwQvV9wrQCvz0dTd4C43942dqahQ9vJD9j/Ulg=; b=Rmk/YRXMndM5TRwCUHK9oVrt6C5XLJHI/dP4jeDkW+jcb4PnTW04RSfMzrYxeFbiHhQndwpMI9ofB09bY4vZUlzaAHE343fZwFt8mfnmZnTXAoURoFnkcuPWBAIwmhYCspGGrVYBDGdZ9zYhPhylq7M97Ws3f7/juF/5HD7+6DHyANq+MDuluV7BIMGmovlhHrfP9V36vstes0VJRNCG3you8qDEF0eES/3IOAUygNo+Qvxtv3/fuUtoJwsYHSegzwWGVRcoLJ16Bg8df98IAKZILbozgDWrD4Y46Ja8tzdu0soNRnB1FwJglp9rn3uUKopuL0vfeCmguDzGcV0log==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=tssdTwwQvV9wrQCvz0dTd4C43942dqahQ9vJD9j/Ulg=; b=c6sYP4TeNgROMIhRrxQHgrXfRIzUdI8h+3Ci7wn7OroWoik34JWX+UrW8ALG5yazvD870gv3IY9UbXEVMjcJFH0deY5E1pLfKIla38kH2ZIw9R9vRokEHZs27EVLVg7toaPU1zh5klR3Ap6jow/v2Ont8G3U9rJPUTDjDWUgQMM=
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com (2603:10a6:10:20d::17) by AS8PR08MB9455.eurprd08.prod.outlook.com (2603:10a6:20b:5ed::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5676.17; Thu, 29 Sep 2022 11:37:14 +0000
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::d48c:61b9:7a6a:88bc]) by DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::d48c:61b9:7a6a:88bc%9]) with mapi id 15.20.5676.020; Thu, 29 Sep 2022 11:37:14 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: "rats@ietf.org" <rats@ietf.org>
Thread-Topic: Removal of the "replay protection and privacy" section in the EAT draft
Thread-Index: AdjT95DcUeBB3MsiQ7iId+dgIoVOIQ==
Date: Thu, 29 Sep 2022 11:37:14 +0000
Message-ID: <DBBPR08MB5915743F728A04E27961AD36FA579@DBBPR08MB5915.eurprd08.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: A0F76C55E67BC947B15B5F8C5CC9871A.0
Authentication-Results-Original: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
x-ms-traffictypediagnostic: DBBPR08MB5915:EE_|AS8PR08MB9455:EE_|AM7EUR03FT007:EE_|DU0PR08MB7740:EE_
X-MS-Office365-Filtering-Correlation-Id: e820c134-b81d-43a9-32c3-08daa20ef9a0
x-checkrecipientrouted: true
nodisclaimer: true
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: +ZZHoCM7MloTkgB0AVoOObRk3fhQdXBhd8FcsIwM0XUyhCKjX8O99lwagDD3P5Sff6vJPRSGrn4FqhZYcZYo4XuaeR+DdELNHU2Xl8lYqgzqDBUbxdYcO7rpIVfcuC8tPpdJ/vHQXv0fzkDMVsqq47wOfOvRrG1EwAS9Nm/X1gR4MNX1N4yiM8cnZzxnM8E0E7XTtYtx7gMltTHMk287s89jDaX+w1yiZwSMaLPAJgXpfmT4JrwKf3e/aVmnlBYGIhV5MNgFQ0qJfGzXq0/0NSy14cRbIpdwf8Lj8MlC3cmozzhznJElXVbZ4XJCA47XsTwnSelLegoVv6FzCyqDnpMuwnWNMr+O6TE9d1Iw9BhG0wdWQkdtoLoWduJsz/go08Jsfr2sw1+LGJM861Rsch/FZMoOhAoAzWnk3qYfsEl0lT7aHA6yzogFInSIjFaOGswlvVgizZN4BRAIhNREqEFIsh4cihdi92d7fEdYh45Sbyzk+3OClyIB7jSKQKtjf6QP6l7Y6gw92DzSq8hts6IUqte0tbsEQ27w+E9mP535UbNaz7cgLK2b/Y5bha5Jo0xt+4TS6iDu5qOF09kWC9dK0shuDlmi86sunNezRRg/9oqUJ02qe2AGtwCU2vNvjA+1LjE49D2goTYtpeHN5BUbLfp2YjGqH60bF7mA1Blh1tiLI+8gO9SHBceOvehKZuIlEjJjZssq9u5A2J5uJAYAOlTgGxEnbgXmhmVt+pjtEOQLUzT/R2bGfrC9LC8McmScdreqGka3s2Sc5MSolTXwfkNFCNRke7BGj1haAlx/x9bzK5ERuG98/1RSyiNCh0NUYOIdkoTHpjKZjep11fq4XBvg+ZRmtP/V8J9asoY=
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBBPR08MB5915.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(376002)(136003)(39860400002)(366004)(396003)(346002)(451199015)(6916009)(316002)(5660300002)(64756008)(52536014)(8936002)(66946007)(33656002)(66556008)(66476007)(55016003)(66446008)(2906002)(41300700001)(8676002)(26005)(9686003)(76116006)(186003)(478600001)(86362001)(7696005)(6506007)(966005)(71200400001)(38100700002)(38070700005)(122000001)(83380400001)(66899015)(12393003); DIR:OUT; SFP:1101;
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR08MB9455
Original-Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM7EUR03FT007.eop-EUR03.prod.protection.outlook.com
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id-Prvs: d2b9e1db-85f3-4656-c96d-08daa20ef480
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: +qqoxsuIM/X61OQjseTxeRlLCO+B/ApT37gMXfAIjFHzfIxZpCg3N0M4xLP+YvomXUjdZxj3ndwAHAZrgdGf5iQALNPWk4xZvgYW/hlezHFrH1N07gRETIyyxR/nOYQHJR5Sl7HjabCqD1HQ4m1UaUZD0ymK5w0KqRyDamu9f7DhyoAT4HmcfpCX36H2JSqVT8WbDp8b2nCkKAj3ngvMHu4eNyAmx+wHinMlCpxoboiE4bVjHdr3zqcvXP8xp68XHkKKOVjINYWUFr0s8jMacDQZ7f6pDS16zdR+MMfyqN2X+lOWyh/pUXjA6NsR1fjj+3X6w95zeseVYA9940vDwLNK6NRAKb4SIn+TUyTzmzVbOdkl6hE2NzDjX9L0+R7fNycKPfGOfETJ5REpApulmptGHzKqWEGq0DkbmLr9okB2bm9dUntWYQde8KDsgtFLwGkxGNdWXlL0ZcPsYPb84h96HdPHbEcBqZmADkDB8m4PbY2RbHwy/4spEcd1V7yt/e31+4KSf7ElwLVLNKI6B7ZozKAche4tLuVDaXFYSyQZaCzTquBFGQFIg+ofzEHmypZhAEaUEHngklb4SGF6IeSWd/oudgN5J8A2l0YuC7EaxbH/b+f6c37S63mPwBcv+5lPeN5JvmhHXw9vD4JohXUfMk0J8r/Sbw0TIxxjGTzwpX6oAfr1tU9Oo5iKHFgjrs7pDjKfXU93s5KH5e+3JFApB14IDkvHFwhnMDw0DSTVuO5VPuhJr9Pr/H3E8xU7gaK/km9v7m0Oq9Pm4hGPqLkx1HIZNBtqvaYEKVrKT+gS2NXR4h2UsNgSIfo6UUxE4A23chbXLmWxR+dl/b84xBMMOUrjfn1W2IX8sfNwtjo=
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(13230022)(4636009)(39860400002)(346002)(396003)(136003)(376002)(451199015)(36840700001)(40470700004)(46966006)(82740400003)(40460700003)(33656002)(82310400005)(356005)(86362001)(8676002)(81166007)(26005)(52536014)(70206006)(70586007)(6506007)(9686003)(41300700001)(186003)(55016003)(8936002)(7696005)(478600001)(316002)(6916009)(966005)(40480700001)(36860700001)(47076005)(336012)(5660300002)(83380400001)(2906002)(66899015)(12393003); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 29 Sep 2022 11:37:22.7145 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: e820c134-b81d-43a9-32c3-08daa20ef9a0
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: AM7EUR03FT007.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0PR08MB7740
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/9bTcjbvnK8sYMX9czQF6TIaYChQ>
Subject: [Rats] Removal of the "replay protection and privacy" section in the EAT draft
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Sep 2022 11:37:33 -0000

Hi all,

In PR https://github.com/ietf-rats-wg/eat/pull/299 I proposed a
re-write of the privacy consideration section.

As part of my re-write I removed text that was, according to Giri,
"reviewed and agreed upon by the Architecture team and EATS
editors in https://github.com/ietf-rats-wg/eat/pull/164".

Now, I would like to bring it to the group. Here is the relevant text:

8.4.  Replay Protection and Privacy

   EAT offers 2 primary mechanisms for token replay protection (also
   sometimes known as token "freshness"): the cti/jti claim and the
   nonce claim.  The cti/jti claim in a CWT/JWT is a field that may be
   optionally included in the EAT and is in general derived on the same
   device in which the entity is instantiated.  The nonce claim is based
   on a value that is usually derived remotely (outside of the entity).
   These claims can be used to extract and convey personally-identifying
   information either inadvertently or by intention.  For instance, an
   implementor may choose a cti that is equivalent to a username
   associated with the device (e.g., account login).  If the token is
   inspected by a 3rd-party then this information could be used to
   identify the source of the token or an account associated with the
   token (e.g., if the account name is used to derive the nonce).  In
   order to avoid the conveyance of privacy-related information in
   either the cti/jti or nonce claims, these fields should be derived
   using a salt that originates from a true and reliable random number
   generator or any other source of randomness that would still meet the
   target system requirements for replay protection.

The RATS architecture talks about three approaches for providing freshness,
namely
- timestamps,
- nonces, and
- epoch IDs.

The text above talks about two mechanisms, namely
- nonces, and
- the cti/jti.

(As you will see later, the cti/jti does not correspond to one of the freshness mechanisms
from the RATS architecture.)

In the EAT draft version -14 the cti/jti claims are mentioned in two sections, namely
in Section 8.4 (see above) and also in Section 4.3.1. The cti claim contains a unique identifier for the JWT.

Assuming that an implementer uses the cti to convey a username / account login is
unjustified given what Section 4.1.7 of RFC 7519 defines it to be, see
 https://www.rfc-editor.org/rfc/rfc7519#section-4.1.7.

So, there is only a privacy problem with the cti/jti if you use it in a way
that has not been envisioned and even suggested by the RFC that defined it.

The privacy implications of the nonce are not described nor are other privacy
implications of the iat (issued at) claim defined, which would correspond to
the timestamp replay protection mechanism defined in the RATS architecture.

For this reason I suggested to remove this text from the privacy consideration section.

Ciao
Hannes



IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.