[secdir] secdir review of draft-ivov-grouptextchat-purpose-03

Leif Johansson <leifj@sunet.se> Mon, 22 July 2013 11:58 UTC

Return-Path: <leifj@sunet.se>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CCE0221E8051; Mon, 22 Jul 2013 04:58:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tEprpDWxZUti; Mon, 22 Jul 2013 04:58:08 -0700 (PDT)
Received: from e-mailfilter02.sunet.se (e-mailfilter02.sunet.se [IPv6:2001:6b0:8:2::202]) by ietfa.amsl.com (Postfix) with ESMTP id 035B421E8091; Mon, 22 Jul 2013 04:58:07 -0700 (PDT)
Received: from smtp1.nordu.net (smtp1.nordu.net [IPv6:2001:948:4:6::32]) by e-mailfilter02.sunet.se (8.14.3/8.14.3/Debian-9.4) with ESMTP id r6MBw34W032261 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 22 Jul 2013 13:58:03 +0200
Received: from [109.105.104.183] (dhcp49.se-tug.nordu.net [109.105.104.183]) (authenticated bits=0) by smtp1.nordu.net (8.14.6/8.14.6) with ESMTP id r6MBw0sq019554 (version=TLSv1/SSLv3 cipher=DHE-RSA-CAMELLIA256-SHA bits=256 verify=NO); Mon, 22 Jul 2013 11:58:02 GMT
Message-ID: <51ED1E48.90307@sunet.se>
Date: Mon, 22 Jul 2013 13:58:00 +0200
From: Leif Johansson <leifj@sunet.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20130623 Thunderbird/17.0.7
MIME-Version: 1.0
To: secdir@ietf.org, iesg@ietf.org, draft-ivov-grouptextchat-purpose.all@tools.ietf.org
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
X-p0f-Info: os=unknown unknown, link=Ethernet or modem
X-CanIt-Geo: ip=109.105.104.183; country=SE; region=26; city=Stockholm; latitude=59.3333; longitude=18.0500; http://maps.google.com/maps?q=59.3333,18.0500&z=6
X-CanItPRO-Stream: outbound-nordu-net:outbound (inherits from outbound-nordu-net:default, nordu-net:default, base:default)
X-Canit-Stats-ID: 0aK3nW3Ip - 98c654b43432 - 20130722
X-Antispam-Training-Forget: https://mailfilter.nordu.net/canit/b.php?i=0aK3nW3Ip&m=98c654b43432&t=20130722&c=f
X-Antispam-Training-Nonspam: https://mailfilter.nordu.net/canit/b.php?i=0aK3nW3Ip&m=98c654b43432&t=20130722&c=n
X-Antispam-Training-Spam: https://mailfilter.nordu.net/canit/b.php?i=0aK3nW3Ip&m=98c654b43432&t=20130722&c=s
X-CanIt-Archive-Cluster: PfMRe/vJWMiXwM2YIH5BVExnUnw
X-Scanned-By: CanIt (www . roaringpenguin . com)
Subject: [secdir] secdir review of draft-ivov-grouptextchat-purpose-03
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Jul 2013 11:58:08 -0000

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written primarily for the benefit of the
security area directors.  Document editors and WG chairs should treat
these comments just like any other last call comments.

I found the document reasonably well written and easy to understand.
The security considerations section does a fair job of identifying the
threats.

I would have liked to see a little bit more concrete guidance for
implementers about how to handle the identified threats for the
most common text chat protocols identified in the text (eg xmpp,
irc & "web chats") though.

        Best R
        Leif