Re: [saag] Interest COVID-19 'passport' standardization?
Henry Story <henry.story@gmail.com> Mon, 02 August 2021 11:41 UTC
Return-Path: <henry.story@gmail.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id C3F5F3A19E0
for <saag@ietfa.amsl.com>; Mon, 2 Aug 2021 04:41:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001]
autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id 1k9IniGdbSsG for <saag@ietfa.amsl.com>;
Mon, 2 Aug 2021 04:41:13 -0700 (PDT)
Received: from mail-wm1-x333.google.com (mail-wm1-x333.google.com
[IPv6:2a00:1450:4864:20::333])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id A5FA53A19DD
for <saag@ietf.org>; Mon, 2 Aug 2021 04:41:12 -0700 (PDT)
Received: by mail-wm1-x333.google.com with SMTP id
f9-20020a05600c1549b029025b0f5d8c6cso697367wmg.4
for <saag@ietf.org>; Mon, 02 Aug 2021 04:41:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;
h=mime-version:subject:from:in-reply-to:date:cc
:content-transfer-encoding:message-id:references:to;
bh=5RGQspo5ZMC8IgVzGqB1TRTA76FJw5mxRYeRsP1BdTI=;
b=AHSB4k2sugPe12Ayh4UTL35QSynoqBvLIQrsS1AWwxyqkf9SAhMC7IdGptHeoLWHXo
Ug9TFeB0IRy5xUBXIU6Z2FCbuilt+QZyzwALAds/0Cmn/rVW/yuwARxGgUjuF//TahrB
b3GeuLcAm9MjcA1L+CGO87/Sq6L+pkH0wShQZIZA2VTXekB+QY43adrDzP/9eFufp2o4
JORScnbw/fknFXHqRhyMG1Q0wiEq29fjUMK+w7HckrI7vCigl7eTOR/kMqs2qlLcBhi8
wHU187UUfO5HFK8fW+LMQYOtKLZkRP8/7miLJPv8XutjNbfw6BI3Oh80P6VxLGuIeEj9
263w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20161025;
h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc
:content-transfer-encoding:message-id:references:to;
bh=5RGQspo5ZMC8IgVzGqB1TRTA76FJw5mxRYeRsP1BdTI=;
b=J0acj6eXaEDuACNv/XbfQZyaBVZ9Pweq0ywUkOaqLxgzlVybQBl1bDDXABPkqnIPBL
fGfqvdMTOZappWSgPohZvr/GSsifXGTSbBTNQQp9i0hWSLI1u3BwAcmBXSQ1jUU/OH36
dpSwv/Ba9QOFT3N91oCFRoYvqG5FcqFnpuH/baaTZbzUR1/2PnUS9vKTD8igFmWZXI6r
GhgQ2iLaj5IseYebu6KDLOb2Znat6s1kxq3Mq8R8bSmHfftRBzoEKDdlubezqcM87V0Q
D80IAW7+5n/yUzZJH+D7u/09nYs5ZmY61j0A1sm7FfyzF24JGR9aKaa5mNKHH9yvCfS0
DGkA==
X-Gm-Message-State: AOAM530E3NjUGV94LLpwCHwovz3TShjkV6Uhp8HInbnpGw5M4zQVKvUz
fZkhF3VDTssSTUR9ECbxGBo=
X-Google-Smtp-Source: ABdhPJxX46DJnN0sgDBNoVttxA7amyvFpru2/yyhoflrp4qpQ/dqlmxWpX0E6XRlkkVrKw5tPdDczw==
X-Received: by 2002:a7b:c353:: with SMTP id l19mr7904162wmj.127.1627904470401;
Mon, 02 Aug 2021 04:41:10 -0700 (PDT)
Received: from smtpclient.apple (pop.92-184-104-4.mobile.abo.orange.fr.
[92.184.104.4])
by smtp.gmail.com with ESMTPSA id q5sm11401438wrx.33.2021.08.02.04.41.08
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Mon, 02 Aug 2021 04:41:09 -0700 (PDT)
Content-Type: text/plain;
charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 15.0 \(3686.0.1.2.1\))
From: Henry Story <henry.story@gmail.com>
In-Reply-To: <CADPMZDBu2cbtWk7Y4YMKXOWXQoKsBkAD9D1AuC_Rp+9xHawX7w@mail.gmail.com>
Date: Mon, 2 Aug 2021 13:41:07 +0200
Cc: IETF SAAG <saag@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <E0FDB1EE-256D-4925-9EE7-49DE212BFF02@gmail.com>
References: <CAE1ny+4QdmSJS-spV6Do5yDs1x3iAwyHdSx=Oa+cRXU+ESZ2nA@mail.gmail.com>
<CADPMZDBu2cbtWk7Y4YMKXOWXQoKsBkAD9D1AuC_Rp+9xHawX7w@mail.gmail.com>
To: denis bider <denisbider.ietf@gmail.com>
X-Mailer: Apple Mail (2.3686.0.1.2.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/Y4UCXH72PuADlPGQls558dc5W44>
Subject: Re: [saag] Interest COVID-19 'passport' standardization?
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>,
<mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>,
<mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Aug 2021 11:41:18 -0000
> On 2. Aug 2021, at 12:51, denis bider <denisbider.ietf@gmail.com> wrote: > > Covid-19 vaccine passports are the stupidest, most oppressive shit > that needs to be resisted at all levels. > > Given information we have now, I cannot respect anyone who still > accepts any of the Covid-19 vaccines. > > The vaccines do NOT stop transmission. They do NOT reduce deaths. They > just redistribute deaths from average age 80+ with comorbidities, to > younger people by giving myocardial infarctions to children and young > adults. > > There is no medical justification to force these vaccines on anyone. > Individually, there is no benefit given the information we already > know, for nearly anyone, in nearly any risk group. > > For a healthy individual to accept these vaccines is stupid. For > governments and businesses to force them on people is monstrous and a > crime against humanity. > > Long-term, we do not know anyone who survived 2 years or more after > taking these vaccines. Please try to refute that statement. > > Anyone who conducts work that enables the forcing of these vaccines, > and the arrival of mandatory vaccine passports, is a Dr. Mengele and > should expect a trial before a tribunal with penalties up to and > including death. > > I am serious. Do not do these fucking things. Heh. Nice to have a strong position like that. :-) Of course all tools are double edged, right since Prometheus stole the fire from the Gods to give it to us mortals, for which it is well known Zeus punished him to eternally be tied to a rock, and every day have an eagle eat out his liver. https://en.wikipedia.org/wiki/Prometheus Cars kill people, medicaments too, and so does sugar and food when eaten in unhealthy quantities, a problem in many countries ever since industrialization made foods cheap and available. Societies counter such problems by creating cultural antibodies through education: one has to learn to eat less in a society such as ours, one has to learn to drive carefully to not kill people (and for that we have developed tests such as drivers licenses), and it is not advisable to get drugs prescribed by some dude on the corner of the street: we have certified doctors and apothecary’s for that. I agree also that one should not force people to be vaccinated. Some people react very badly to them: I heard a story this week in our town here. But Verifiable Credentials could also be used to hold a ”proof of not having the virus at time T” if needed, or even a proof of having had it, which should be as good as having had a vaccine. In the end we are all going to get it: vaccines rollouts are indeed aiming at doing just that. So that is why I would not be that worried about privacy with such Credentials. Furthermore, not everything in a credential needs to be private: certainly not the id of the signing authority as they are making the claim, and need to be known as capable of making them. Note that privacy *is* really important criterion for any tracing app, which have already been rolled out, btw independently of certificates. So just as with the virus, it’s all very complicated. A year ago, I spent way too long studying this. Some of my thoughts then were collected in ”Co-immunology and the web” https://blog.usejournal.com/co-immunology-and-the-web-43379b46688e Hope that helps, Henry > > On Fri, Jul 30, 2021 at 1:17 PM Harry Halpin <hhalpin@ibiblio.org> wrote: >> >> Everyone [and apologies if you already got this message on CFRG or SECDISPATCH], >> >> While the research community and industry was very quick to work on privacy-enhanced contact tracing, I've seen very few people taking the much more pressing issue of COVID-19 passports. >> >> If this IETF111 was in person, we could have done an informal BoF, but as its' not, I'm sending out an email to gauge interest. >> >> I've earlier seen some very badly done academic work using W3C "Verified Credentials" and W3C Decentralized Identifier (DID) standards [1]. However, while a bunch of sketchy blockchain technology has not been adopted (so far, although I believe IATA and WHO are still being heavily lobbied in this direction), there has been the release of the EU "Green" Digital Credentials that actually uses digital signatures. >> >> However, there's a number of problems: >> >> * No revocation in case of compromise >> * Privacy issues, i.e. leaking metadata >> * Limited key management (booster shots might require) >> * No use of standards for cross-app interoperability >> >> Furthermore, there appears to be differences between countries, and some countries do not use cryptography at all (the US). Therefore, as an American in France who flew home ASAP to get vaccinated in the US, as a consequence of this lack of interoperability I can't travel on trains or eat at restaurants easily, despite being vaccinated. I imagine this will become a larger problem. >> >> I have a report I'm willing to share, but I'd first like to know if there's any interest in standardization on this front at the IETF despite this topic being, I suspect, a bit of astretch of our remit. However, we live in interesting times. >> >> I don't think the W3C (or the ITU, etc.) has the security expertise, and while the crypto and security/privacy here is pretty simple, I think it should happen somewhere. >> >> While I originally polled it by CFRG IRTF to see if there was any interest whatsoever, Benjamin Kaduk pointed out SAAG and SECDISPATCH would be better places to start. I'd like to know what others think. >> >> yours, >> harry >> >> [1] https://arxiv.org/abs/2012.00136 >> _______________________________________________ >> saag mailing list >> saag@ietf.org >> https://www.ietf.org/mailman/listinfo/saag > > _______________________________________________ > saag mailing list > saag@ietf.org > https://www.ietf.org/mailman/listinfo/saag
- [saag] Interest COVID-19 'passport' standardizati… Harry Halpin
- Re: [saag] Interest COVID-19 'passport' standardi… Eric Rescorla
- Re: [saag] Interest COVID-19 'passport' standardi… Volker Birk
- Re: [saag] Interest COVID-19 'passport' standardi… Harry Halpin
- Re: [saag] Interest COVID-19 'passport' standardi… Carsten Bormann
- Re: [saag] Interest COVID-19 'passport' standardi… Henry Story
- Re: [saag] Interest COVID-19 'passport' standardi… Eric Rescorla
- Re: [saag] Interest COVID-19 'passport' standardi… Dirk-Willem van Gulik
- Re: [saag] Interest COVID-19 'passport' standardi… Dirk-Willem van Gulik
- Re: [saag] Interest COVID-19 'passport' standardi… Dirk-Willem van Gulik
- Re: [saag] Interest COVID-19 'passport' standardi… Volker Birk
- Re: [saag] [Secdispatch] Interest COVID-19 'passp… Harry Halpin
- Re: [saag] [Secdispatch] Interest COVID-19 'passp… Dirk-Willem van Gulik
- Re: [saag] [Secdispatch] Interest COVID-19 'passp… Volker Birk
- Re: [saag] [Secdispatch] Interest COVID-19 'passp… Kathleen Moriarty
- Re: [saag] [Secdispatch] Interest COVID-19 'passp… Volker Birk
- Re: [saag] Interest COVID-19 'passport' standardi… Stephen Farrell
- Re: [saag] Interest COVID-19 'passport' standardi… Carsten Bormann
- Re: [saag] Interest COVID-19 'passport' standardi… Stephen Farrell
- Re: [saag] Interest COVID-19 'passport' standardi… Metapolymath Majordomo
- Re: [saag] Interest COVID-19 'passport' standardi… Carsten Bormann
- Re: [saag] Interest COVID-19 'passport' standardi… Eliot Lear
- Re: [saag] [Secdispatch] Interest COVID-19 'passp… Michael Richardson
- Re: [saag] Interest COVID-19 'passport' standardi… Michael Richardson
- Re: [saag] Interest COVID-19 'passport' standardi… Stephen Farrell
- Re: [saag] Interest COVID-19 'passport' standardi… denis bider
- Re: [saag] Interest COVID-19 'passport' standardi… Henry Story
- Re: [saag] Interest COVID-19 'passport' standardi… Dirk-Willem van Gulik
- Re: [saag] Interest COVID-19 'passport' standardi… Henry Story
- Re: [saag] Interest COVID-19 'passport' standardi… Dirk-Willem van Gulik
- Re: [saag] Interest COVID-19 'passport' standardi… Carsten Bormann
- Re: [saag] Interest COVID-19 'passport' standardi… Henry Story
- Re: [saag] Interest COVID-19 'passport' standardi… Dirk-Willem van Gulik
- Re: [saag] Interest COVID-19 'passport' standardi… Thomas Hardjono
- Re: [saag] Interest COVID-19 'passport' standardi… Carsten Bormann
- Re: [saag] Interest COVID-19 'passport' standardi… Eric Rescorla
- Re: [saag] Interest COVID-19 'passport' standardi… Carsten Bormann
- Re: [saag] Interest COVID-19 'passport' standardi… Eric Rescorla
- Re: [saag] Interest COVID-19 'passport' standardi… Tim Bray
- Re: [saag] Interest COVID-19 'passport' standardi… Eric Rescorla
- Re: [saag] Interest COVID-19 'passport' standardi… Tim Bray
- Re: [saag] Interest COVID-19 'passport' standardi… Jon Callas
- Re: [saag] Interest COVID-19 'passport' standardi… Stephen Farrell
- Re: [saag] Interest COVID-19 'passport' standardi… Tim Bray