[secdir] SECDIR review of draft-ietf-marf-redaction-08

Julien Laganier <julien.ietf@gmail.com> Wed, 08 February 2012 18:19 UTC

Return-Path: <julien.ietf@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1031421E8015; Wed, 8 Feb 2012 10:19:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VjVKhcQLM3sr; Wed, 8 Feb 2012 10:19:18 -0800 (PST)
Received: from mail-yx0-f172.google.com (mail-yx0-f172.google.com [209.85.213.172]) by ietfa.amsl.com (Postfix) with ESMTP id 5B0A321E8010; Wed, 8 Feb 2012 10:19:18 -0800 (PST)
Received: by yenm3 with SMTP id m3so486636yen.31 for <multiple recipients>; Wed, 08 Feb 2012 10:19:18 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; bh=KYHz8YrIjACMt41tUEdIJ1QUe5xByp8SuGOosOorEBk=; b=TYl6xDq0pHQPS/CgRek340NdkW1SCcW+04o0gqykRIKLf6JzDQ5/khbjakTr3fq2SZ sW606H4XpzcEPr0c+orb7LGjGEyUO5Y9s4G7BGbLGkYBygEyxqvM7DkFNQiE0XrUdjwq 03qduNVpdCNaSArYebVp1uePlxdfoGAf2CN8s=
MIME-Version: 1.0
Received: by 10.101.141.8 with SMTP id t8mr11534097ann.71.1328725158013; Wed, 08 Feb 2012 10:19:18 -0800 (PST)
Received: by 10.146.67.39 with HTTP; Wed, 8 Feb 2012 10:19:17 -0800 (PST)
Date: Wed, 08 Feb 2012 10:19:17 -0800
Message-ID: <CAE_dhju-P1L4Qg0xeKADCCe6g_g1KPZpNVRKSdxyD8-ySG0voA@mail.gmail.com>
From: Julien Laganier <julien.ietf@gmail.com>
To: The IESG <iesg@ietf.org>, secdir@ietf.org, draft-ietf-marf-redaction.all@tools.ietf.org
Content-Type: text/plain; charset="ISO-8859-1"
Subject: [secdir] SECDIR review of draft-ietf-marf-redaction-08
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 08 Feb 2012 18:19:19 -0000

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written primarily for the benefit of the
security area directors.  Document editors and WG chairs should treat
these comments just like any other last call comments.

This document suggest a method to redact private and/or sensitive
portions (e.g., email addresses) of abuse reports in the messaging
infrastructure. The proposed method enables a report receiver to
correlate reports that might refer to a common but anonymous source.

I believe that the proposed method is ok and that its security and
privacy implications are adequately analyzed.

--julien