Re: [saag] Liking Linkability

Mo McRoberts <Mo.McRoberts@bbc.co.uk> Sun, 21 October 2012 08:24 UTC

Return-Path: <Mo.McRoberts@bbc.co.uk>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 27D5221F8BAC for <saag@ietfa.amsl.com>; Sun, 21 Oct 2012 01:24:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.999
X-Spam-Level:
X-Spam-Status: No, score=-103.999 tagged_above=-999 required=5 tests=[BAYES_50=0.001, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jpr-Yh+E6Y+y for <saag@ietfa.amsl.com>; Sun, 21 Oct 2012 01:24:04 -0700 (PDT)
Received: from mailout1.mh.bbc.co.uk (mailout1.mh.bbc.co.uk [132.185.144.153]) by ietfa.amsl.com (Postfix) with ESMTP id 4573821F8BA9 for <saag@ietf.org>; Sun, 21 Oct 2012 01:24:03 -0700 (PDT)
Received: from BGB01XI1003.national.core.bbc.co.uk ([10.184.50.53]) by mailout1.mh.bbc.co.uk (8.14.4/8.14.3) with ESMTP id q9L8O1bQ000254; Sun, 21 Oct 2012 09:24:01 +0100 (BST)
Received: from BGB01XUD1009.national.core.bbc.co.uk ([169.254.8.145]) by BGB01XI1003.national.core.bbc.co.uk ([10.184.50.53]) with mapi id 14.01.0355.002; Sun, 21 Oct 2012 09:24:01 +0100
From: Mo McRoberts <Mo.McRoberts@bbc.co.uk>
To: Ben Laurie <ben@links.org>
Thread-Topic: [saag] Liking Linkability
Thread-Index: AQHNr2VswW6Jj4A0pkCv1RVTYc/7Nw==
Date: Sun, 21 Oct 2012 08:24:08 +0000
Message-ID: <A66AA333-283A-4D40-B3BA-DB3AF950252B@bbc.co.uk>
References: <CCA5E789.2083A%Josh.Howlett@ja.net> <tslzk3jsjv8.fsf@mit.edu> <201210181904.PAA07773@Sparkle.Rodents-Montreal.ORG> <FB9E461D-CA62-4806-9599-054DF24C3FD9@bblfish.net> <CAG5KPzxGz+4MywjP4knfbDr2gyvqUZc1HEBXgtaDfYT+DPg5yg@mail.gmail.com>
In-Reply-To: <CAG5KPzxGz+4MywjP4knfbDr2gyvqUZc1HEBXgtaDfYT+DPg5yg@mail.gmail.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [172.19.161.211]
x-exclaimer-md-config: 1cd3ac1c-62e5-43f2-8404-6b688271c769
Content-Type: text/plain; charset="Windows-1252"
Content-ID: <2673411E12372F46AED0DA6D550BB736@bbc.co.uk>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Mailman-Approved-At: Mon, 22 Oct 2012 08:25:26 -0700
Cc: "public-philoweb@w3.org" <public-philoweb@w3.org>, "public-identity@w3.org" <public-identity@w3.org>, "saag@ietf.org" <saag@ietf.org>, "public-privacy@w3.org" <public-privacy@w3.org>, Sam Hartman <hartmans-ietf@mit.edu>, "public-webid@w3.org" <public-webid@w3.org>
Subject: Re: [saag] Liking Linkability
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/saag>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 21 Oct 2012 08:24:36 -0000

On 18 Oct 2012, at 20:29, Ben Laurie <ben@links.org> wrote:

> I really feel like I am beating a dead horse at this point, but
> perhaps you'll eventually admit it. Your public key links you. Access
> control on the rest of the information is irrelevant. Indeed, access
> control on the public key is irrelevant, since you must reveal it when
> you use the client cert. Incidentally, to observers as well as the
> server you connect to.


Right, but that's the nature of a persistent identifier which is (surely) a prerequisite for auth — assuming one doesn't wish to remain anonymous and have some auth, you could hypothetically avoid the cross-domain linkability issue by having a key-per-site, which could be semi-automated on the client side.

What I can't see is how you can maintain persistence on the server side without something which ultimately boils down to (or otherwise allows the storage of) a persistent identifier.

M.

--
Mo McRoberts - Technical Lead - The Space
0141 422 6036 (Internal: 01-26036) - PGP key CEBCF03E,
Zone 1.08, BBC Scotland, Pacific Quay, Glasgow, G51 1DA
Project Office: Room 7083, BBC Television Centre, London W12 7RJ



-----------------------------
http://www.bbc.co.uk
This e-mail (and any attachments) is confidential and
may contain personal views which are not the views of the BBC unless specifically stated.
If you have received it in
error, please delete it from your system.
Do not use, copy or disclose the
information in any way nor act in reliance on it and notify the sender
immediately.
Please note that the BBC monitors e-mails
sent or received.
Further communication will signify your consent to
this.
-----------------------------