Re: [saag] Interest COVID-19 'passport' standardization?

Carsten Bormann <cabo@tzi.org> Fri, 30 July 2021 20:57 UTC

Return-Path: <cabo@tzi.org>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BF8EB3A104E for <saag@ietfa.amsl.com>; Fri, 30 Jul 2021 13:57:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G6hY7YORORhx for <saag@ietfa.amsl.com>; Fri, 30 Jul 2021 13:57:21 -0700 (PDT)
Received: from gabriel-smtp.zfn.uni-bremen.de (gabriel-smtp.zfn.uni-bremen.de [134.102.50.15]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E40BE3A104D for <saag@ietf.org>; Fri, 30 Jul 2021 13:57:20 -0700 (PDT)
Received: from [192.168.217.118] (p548dcc89.dip0.t-ipconnect.de [84.141.204.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by gabriel-smtp.zfn.uni-bremen.de (Postfix) with ESMTPSA id 4Gc08F5wtwz31Td; Fri, 30 Jul 2021 22:57:17 +0200 (CEST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.120.23.2.7\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <CAE1ny+6wZVh1A9yZPfLpuG7AFg5THrY9ie4+QmTsde+DiFHi4w@mail.gmail.com>
Date: Fri, 30 Jul 2021 22:57:17 +0200
Cc: Volker Birk <vb@pep-project.org>, saag@ietf.org
X-Mao-Original-Outgoing-Id: 649371437.3422019-99e5b6aa781e106420961e179b696ab8
Content-Transfer-Encoding: quoted-printable
Message-Id: <7465EFBA-A37A-4CCD-BD0F-63BD202C7AEF@tzi.org>
References: <CAE1ny+4QdmSJS-spV6Do5yDs1x3iAwyHdSx=Oa+cRXU+ESZ2nA@mail.gmail.com> <20210730185749.GA21724@dragon.pibit.ch> <CAE1ny+6wZVh1A9yZPfLpuG7AFg5THrY9ie4+QmTsde+DiFHi4w@mail.gmail.com>
To: Harry Halpin <hhalpin@ibiblio.org>
X-Mailer: Apple Mail (2.3608.120.23.2.7)
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/2ufCudnYoaUgjI5oAXblkXJeQB8>
Subject: Re: [saag] Interest COVID-19 'passport' standardization?
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 Jul 2021 20:57:26 -0000

On 2021-07-30, at 22:40, Harry Halpin <hhalpin@ibiblio.org> wrote:
> 
> While I support your sentiments (in fact, I warned against the persistence and abuse of COVID-19 related infrastructure as soon as the pandemic hit [1]) and do note that the COVID-19 passports have already happened in most countries, particularly in the EU. If they were built with open source and open international standards, with actual privacy and security, then it would be harm minimization. 

There are some components in the EU DGC that we might want to extract and properly specify.

Grüße, Carsten