Re: [saag] Direct trust between users

Phillip Hallam-Baker <phill@hallambaker.com> Thu, 25 April 2019 00:16 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CDF6712047D for <saag@ietfa.amsl.com>; Wed, 24 Apr 2019 17:16:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.647
X-Spam-Level:
X-Spam-Status: No, score=-1.647 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.25, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yJtdHEUxENuf for <saag@ietfa.amsl.com>; Wed, 24 Apr 2019 17:16:11 -0700 (PDT)
Received: from mail-oi1-f172.google.com (mail-oi1-f172.google.com [209.85.167.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5D3321201D4 for <saag@ietf.org>; Wed, 24 Apr 2019 17:16:11 -0700 (PDT)
Received: by mail-oi1-f172.google.com with SMTP id v10so15770428oib.1 for <saag@ietf.org>; Wed, 24 Apr 2019 17:16:11 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=P+QUl9lb7mt4lDyWIxrzDkK9UsLQjlxdaU2tK0NLyTI=; b=Vdy1KceQ7lGoSpK7wJcxQjArPYgsuRN1eWevJP+nIWu2Cbkq2Atpj1H90n4OnCN+p2 rWr0Q5eTYD2mnLEslKiODw+yXeUByx7yUgIhKn8xsjCGxAY143lYoqerI0R7QkQTsGeB ZZVIWIedqZYBbKH0RPYzMG+P2pKBfBnkjRF11qssNFm7D2PGdmjzCkFtS4z0hE026GO3 V8vFhDO+GT5PLP9CjBr8+AGq0cRIkYas2HrcS81dnurZuGEWKsHg9pF53wnYddHELwOV ZEQRpNruV2GRHQXMU35M4NT5F+jfODC6poaWxMmUSGf9BfyXVZwuXJeS6fb65y+coxOd oexA==
X-Gm-Message-State: APjAAAWx80byDUL3pztrkTqbRdSiFU/nF/2a7MBoAn5zviyWaRxkcytk a6eHlgOzKwFfRXajvem4dW85HlF9Ohp1PvBrOEU=
X-Google-Smtp-Source: APXvYqwUh/qVBZlNpabAwb+1mGlJKjZ1qFQXURc7BSMpz7GTX1yGR+cPSyXbHEK3XbjGFB29ioRVfL02PN/lOUiHS44=
X-Received: by 2002:aca:5a89:: with SMTP id o131mr1316214oib.17.1556151370550; Wed, 24 Apr 2019 17:16:10 -0700 (PDT)
MIME-Version: 1.0
References: <CAMm+LwheS8mP8guk4++VNSfcp19kqcOZLxCHaV0=F02xyc7Aow@mail.gmail.com> <20190424182641.GL3137@localhost> <CAMm+LwjAPOf9eW9kpHfh=4MmSYLciHBJ4g2Kr32bkejpsdf3Xw@mail.gmail.com> <20190424233338.GP3137@localhost> <50e8ec99-9d2c-bdcc-d906-03288a7a50eb@cs.tcd.ie>
In-Reply-To: <50e8ec99-9d2c-bdcc-d906-03288a7a50eb@cs.tcd.ie>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Wed, 24 Apr 2019 20:15:59 -0400
Message-ID: <CAMm+LwhMbTB=k=Myc4B0BQWPBOHzNB0x68RSZ1wTd4=4Qs=jeQ@mail.gmail.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Cc: Nico Williams <nico@cryptonector.com>, IETF SAAG <saag@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000a8920105874fb958"
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/Ix6fk5-v5ijKPn0hBNwHFUPg0vU>
Subject: Re: [saag] Direct trust between users
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Apr 2019 00:16:13 -0000

On Wed, Apr 24, 2019 at 7:50 PM Stephen Farrell <stephen.farrell@cs.tcd.ie>
wrote:

>
> Just on this point:
>
> On 25/04/2019 00:33, Nico Williams wrote:
> > sure, users can go use onion routing, but good luck with that
>
> Loading [1] (which is the local "newspaper of record") just
> now:
>
> - via FF with NoScript and other blockers: 5.12 seconds
> - via Tor browser bundle (TBB), default settings: 10.24 seconds
> - via Chromium with out of the box settings 12+ seconds
>   (JS+ads kept it spinning 'till 15s in fact but that was
>   just ads changing I think)
>
> Timings are rough, just as shown by n/w debugger UI. But
> this is consistent with other occasions on which I've
> measured.
>
> ISTM that onion routing is less bad, performance wise, than
> accepting JS/advertising and tracking.
>
> I've started encouraging my students to try TBB and consider
> using it when doing e.g. health related searches or whatever
> they'd prefer not be correlated with all the other horrendous
> amounts of data on them slurped up by mega-providers.
>

Onion routing for Web content is tricky because it can be MB

Email is potentially easier as most messages are short unless they have
attachments. So if we restrict messages to 64KB in size and require
anything larger to be sent as an attachment, we can make quite a bit of
headway.