Re: [saag] Interest COVID-19 'passport' standardization?

Carsten Bormann <cabo@tzi.org> Sat, 31 July 2021 15:18 UTC

Return-Path: <cabo@tzi.org>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8FD1A3A0795 for <saag@ietfa.amsl.com>; Sat, 31 Jul 2021 08:18:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tEtqb6KJ9u5w for <saag@ietfa.amsl.com>; Sat, 31 Jul 2021 08:18:04 -0700 (PDT)
Received: from gabriel-smtp.zfn.uni-bremen.de (gabriel-smtp.zfn.uni-bremen.de [IPv6:2001:638:708:32::15]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D6F043A078E for <saag@ietf.org>; Sat, 31 Jul 2021 08:18:03 -0700 (PDT)
Received: from [192.168.217.118] (p548dcc89.dip0.t-ipconnect.de [84.141.204.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by gabriel-smtp.zfn.uni-bremen.de (Postfix) with ESMTPSA id 4GcSZG5YyCz31W4; Sat, 31 Jul 2021 17:17:58 +0200 (CEST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.120.23.2.7\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <09d0a050-781b-a4cc-47bf-d1e652e4c982@cs.tcd.ie>
Date: Sat, 31 Jul 2021 17:17:55 +0200
Cc: Harry Halpin <hhalpin@ibiblio.org>, saag@ietf.org
X-Mao-Original-Outgoing-Id: 649437475.527734-fcd29c36eab51ad7f7347aa321e26eda
Content-Transfer-Encoding: quoted-printable
Message-Id: <266B969A-CBC1-473B-8F5F-D7A31B66DA2C@tzi.org>
References: <CAE1ny+4QdmSJS-spV6Do5yDs1x3iAwyHdSx=Oa+cRXU+ESZ2nA@mail.gmail.com> <09d0a050-781b-a4cc-47bf-d1e652e4c982@cs.tcd.ie>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
X-Mailer: Apple Mail (2.3608.120.23.2.7)
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/BqMU1RCGMpKtr6Y8Dyi8-r9rOf8>
Subject: Re: [saag] Interest COVID-19 'passport' standardization?
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 31 Jul 2021 15:18:09 -0000

On 2021-07-31, at 16:44, Stephen Farrell <stephen.farrell@cs.tcd.ie> wrote:
> 
> I don't believe the IETF ought be active in this space.
> 
> For their originally designed purpose (cross border travel),
> these systems seem mostly ok as traditional passports will
> also be shown at the same time. I don't see that the travel
> authorities need help from the IETF for that.
> 
> We are seeing significant feature-creep e.g. these QR codes
> are now being required for indoor dining here in Ireland at
> the moment. The scanning technology offered to venues by the
> Irish govt at the moment is an awful online web page [1] to
> which all the QR code data is sent (so govt servers get to
> see who enters where, when, even though they say they don't
> store any of that). That system is likely (IMO) to be widely
> ignored within weeks of it's unwise introduction. We'd be far
> better to stay uninvolved there too IMO.

I don’t understand why the fact that governments buy inane applications (*) should prevent us from thinking about this space.  Patrik’s base45 draft is a nice example where we knew from the outset that the spec was suboptimal (in deployability, fortunately not in security).

Just because, er, foobook.com is reached via TLS doesn’t mean we have to stop supporting TLS :-)

Grüße, Carsten

(*) here in Germany we have the “Luca” app with an abysmal privacy design, which is often called “Luca-schenko” (schenken = giving a gift to someone) because some federal states paid huge amounts of money for no good reason to the instigators, which include a hip-hop star; you couldn’t make this up.