Re: [secdir] Secdir last call review of draft-ietf-tls-dtls-connection-id-11

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Thu, 06 May 2021 09:06 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 84C353A1927; Thu, 6 May 2021 02:06:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=sgaqqUWg; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=sgaqqUWg
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p5vxkfrOABii; Thu, 6 May 2021 02:06:43 -0700 (PDT)
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-eopbgr60085.outbound.protection.outlook.com [40.107.6.85]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C972D3A190A; Thu, 6 May 2021 02:06:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=X+nZX2jPWURfObUzs3fHBUpXXGtF3FWZrX2BeNg9rao=; b=sgaqqUWg4gMV+lXKNt6b0bNUd7xywRWvKbNAyjSn5MV7Qrd1uHsZV8KDrow6PyGz9cL9x4IsXXPphrAY7NCrDJ8MaFrv+wTtRt2qH6IEFXXsDUaVMg5HIvzSiXaG4IJoPkYvG71CmEUAGoeKm8u9FuW4SWfA+T0n94mIH9e+6x8=
Received: from AM7PR02CA0010.eurprd02.prod.outlook.com (2603:10a6:20b:100::20) by VI1PR0802MB2526.eurprd08.prod.outlook.com (2603:10a6:800:b5::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4065.25; Thu, 6 May 2021 09:06:38 +0000
Received: from AM5EUR03FT004.eop-EUR03.prod.protection.outlook.com (2603:10a6:20b:100:cafe::7) by AM7PR02CA0010.outlook.office365.com (2603:10a6:20b:100::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4108.25 via Frontend Transport; Thu, 6 May 2021 09:06:38 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM5EUR03FT004.mail.protection.outlook.com (10.152.16.163) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4108.25 via Frontend Transport; Thu, 6 May 2021 09:06:38 +0000
Received: ("Tessian outbound 6c4b4bc1cefb:v91"); Thu, 06 May 2021 09:06:38 +0000
X-CR-MTA-TID: 64aa7808
Received: from fbcce93529ce.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 2B1F9937-4FE7-4D44-8B36-7AA55F1F2CAE.1; Thu, 06 May 2021 09:06:32 +0000
Received: from EUR05-DB8-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id fbcce93529ce.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Thu, 06 May 2021 09:06:32 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=UhEAEDl/YRZqMlBw7MAWCYjr+FnNjY37FKrjzFsV72mDMzAVNSqwFepe+BAo/MqZ5ZMWmgDtM0QC0ozmo8fA7O0NILjGzIFJfoFJLlcZsGMgNpUVgricmADpRD9u8FbRr7Vpd6jenDaY7kPk/83agan2qOPU8SmLz2+88J+qzU/jUNmCrwkWAftVqy1bkExD+CPImgcGe6GYLl4Zc+jSawAA8rU1ik2BRlqLFzq6wHsVLefkr69TDvxbp9tyOREqoqyCh622AO89l9Op21iCeQaHw52AL5VEj4tVdwVWgk5zev4nKgvT++d/R0GeEeZvmNqTeVCuljM3ut1vtTbbZA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=X+nZX2jPWURfObUzs3fHBUpXXGtF3FWZrX2BeNg9rao=; b=knWhYhlkpMVyC7qHxftH4/NJlvRNamQC3IrYadMFslJ/P8ja58eM1/hqB9XC35CDiJtqz6MAEJeRow/4mu2LEp/obdAH0wK8HlMJmyUHYHtRpDEq2wiJ6eRW9dprVxm3iFntz6nj/gQ4BmR//4ttscT2xWgspZZk0ru59bofenQRVc7WXlfE1twfzev/ynvcjTO6GNKApBIg4Q+DoiyNfdG61J2HGLquP9xeSvCzvbOA3VR5A9TO7BEgTmQn8OxDsABmNYt4JTpCOAhJq++7Bc++FKV7VFSM/vSx0pcxlbytKOZRwHobzbWrYO4A7IGjCmZhqDfAy+Ul8hLsJuSL2g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=X+nZX2jPWURfObUzs3fHBUpXXGtF3FWZrX2BeNg9rao=; b=sgaqqUWg4gMV+lXKNt6b0bNUd7xywRWvKbNAyjSn5MV7Qrd1uHsZV8KDrow6PyGz9cL9x4IsXXPphrAY7NCrDJ8MaFrv+wTtRt2qH6IEFXXsDUaVMg5HIvzSiXaG4IJoPkYvG71CmEUAGoeKm8u9FuW4SWfA+T0n94mIH9e+6x8=
Received: from VI1PR08MB2639.eurprd08.prod.outlook.com (2603:10a6:802:25::13) by VI1PR08MB4128.eurprd08.prod.outlook.com (2603:10a6:803:e9::31) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4108.25; Thu, 6 May 2021 09:06:31 +0000
Received: from VI1PR08MB2639.eurprd08.prod.outlook.com ([fe80::99ef:85aa:3465:475e]) by VI1PR08MB2639.eurprd08.prod.outlook.com ([fe80::99ef:85aa:3465:475e%7]) with mapi id 15.20.4108.027; Thu, 6 May 2021 09:06:30 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: Benjamin Kaduk <kaduk@mit.edu>, Daniel Franke <dafranke@akamai.com>
CC: "draft-ietf-tls-dtls-connection-id.all@ietf.org" <draft-ietf-tls-dtls-connection-id.all@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>
Thread-Topic: [secdir] Secdir last call review of draft-ietf-tls-dtls-connection-id-11
Thread-Index: AQHXN41cUEQ7EEAJ/0K7cRzfE/t7PKrPqiWAgAaTahA=
Date: Thu, 06 May 2021 09:06:30 +0000
Message-ID: <VI1PR08MB26392E8400E274C4B1AFC01BFA589@VI1PR08MB2639.eurprd08.prod.outlook.com>
References: <161910581603.10398.13918665853904033223@ietfa.amsl.com> <20210502043549.GF79563@kduck.mit.edu>
In-Reply-To: <20210502043549.GF79563@kduck.mit.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: 45238133A67836488E59F0FCD43E0274.0
x-checkrecipientchecked: true
Authentication-Results-Original: mit.edu; dkim=none (message not signed) header.d=none;mit.edu; dmarc=none action=none header.from=arm.com;
x-originating-ip: [80.92.114.2]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: 85cd486b-797d-44ef-ec61-08d9106e41c9
x-ms-traffictypediagnostic: VI1PR08MB4128:|VI1PR0802MB2526:
X-Microsoft-Antispam-PRVS: <VI1PR0802MB2526F51D8E64E1F2A3DABCFFFA589@VI1PR0802MB2526.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:9508;OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: 0CtIgLFXIEftSvqIqd+mTVoVbKeW2jgKD25g5k3xEWf6ZdlvHkVku4y0rSjbLblK/v8VtkpSIVZpz5Zdn+QDbXgHoV5eVn0l+/HJM2Dq8D2e5/9i4ZzK+B+q2PYDOLVm7LzirEDlqhIh2mTnWX7DKuIAxvIbXixziM9D6X6Xqdk44JiKqA7umRsLmrdDB2N7z3WSsHrBoP09H+cZybdcG86eYu/6bI27Z6l+0T9OObg5sB3Nvz8llTt+C6E1/tNeFZCL//xaWwdgCboUvmj+HNXNDnZoVISNE9Jg/Ln6g+2aUjRJfZRb7Er3npI5n+G/29/ltS6YPgAMGrKX9s2VVgrLyfSAMQsepUio+CHj384ZNjOeTECOuZlNpyiCY9mMEkS6/Urb2R3F+iHpoRxZMw8/6BHUtYOi/ZsxOCn/ozaOJjb0GnE3aePSFIMDSMxNzepRmsRd3HbfJC15dlxrpnR+9VjZtOiiChCuPKvBhw2wG219aTqIeDuLXWMn3laLFhLIDnb0yZT/HFri/vIwAOr3HYTROgT5TfOTkmJo0N+GX87spE1BztDELT1867ZJy1b6tS/pdBwzMeJFwU3sbOsd59ZAa6+7PZfN6pJRIll7ZOWxZm4NJNE0wbGkqdKnl2iTDs/JIQpNHqDMM1IDA4kMj57qyX/P93kab7dIqJndz0/0D4GVU3Kix3NdqdGV
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:VI1PR08MB2639.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(396003)(136003)(346002)(376002)(39860400002)(76116006)(316002)(66946007)(55016002)(110136005)(83380400001)(122000001)(33656002)(86362001)(4326008)(38100700002)(54906003)(66476007)(66556008)(66446008)(9686003)(478600001)(64756008)(7696005)(2906002)(52536014)(8676002)(186003)(966005)(71200400001)(6506007)(8936002)(26005)(5660300002)(53546011); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: NOAL/Vthqtan/Yy6xfgv8F6k0VE6LLQ00xT6UsQLOUmWs0ON0GgwLkrYy1inJfYIu0yTpd5ZK9jTQUmKfjp1QSQXL+MCl0QmOAWIw3nn8mBMyRelEGGDCSnCSZSdCmEMXQLt1VxegvJYGlRbx2CNsBM58K68G2MIm3ZaevWKHWlO7SYQJZM1IX4SyTJfbKpvhS/jIn/geNFbtaGxAweNBHTWCNsqvhQVShJX4MvJ1/BCShVdXxYPMbdR0v1dnhOT3sPslrSFMvpGoXKyUNj46Vf0eXxobWY1grJI52/cEnB8XWK2x3Hd3mKRb+JR4yTdBi/rTPGKhoU8w+BmN3NVn+4iKUB/X5blPhyMWDi0lTBC+jIIdfOBhAS2AHzx+QI/uqf465P7ybVOERoCqeAtq7TL7LMvP+N2Qjus70bbaYdtxLYwNTj9dnJvcaNZ46l1VpV2gEjDLDKrWrtSfUmkutpzPnoEChj/xFVN2Y1VrQuyijlp79s6AT9Ng9u3RB/QT5jwM26V/pi/z2CyoIK8QDxqdzMUrdAXYIdJ+fBYbXeDAEaxTZhR/Bk3ngan8PKuuYPIEiCxPiY4zhD6aZN8n6ryQvaHusRY42pxsIdpL85uxLjeNf76sPc0+beR3kG388+9ShnS5MR1VRVjcbueAXCa1gJ3MrFFTB46zphfSPw4W9GDaYWHK1pS3gY4+jyZWs3hDWqVe6MmtrP4YE3RcTNW0rmymO1K5DO+Lnv23Z5B+nbpS7sbFLQ1mrbnyO9Udluwueer4uZsZoixFHQ1643Wzzj6XO1FNR57HwM8mCgop6Ql5ndqdLPtNE9JJlPL3hDiPKekfYkHf3FMWZkZMoygLtRnSaROdFEb0pMljJYQ02ZMclOoiiOiZSR9TjICyo7ZFfYXKq0+ZPk7kDTcTco596L3yCK/hB/JvbDLt5tqefr4imxarXG/1Rvlr7sQ01vALVwRdiXofuSo0NqUiJG7HmP3DrhYCzpR20h38Qhc4SM9sIJOxRiI4YTG78FA+COf3OTagpNE1mstAWKE301uP+eGAYMUS3k6v8boZiuZKzwBdfk3Ak4q8MIO7ZlWv5VZrnprF42SX/AtmV24EcOhJtnFFVycBSFQdFitcsrxNHRpUIOUNLQx3AIOXI3nzEnD7To3bpYv/8HENVakywY1uJvU2eQFlS2B+x+RNaZd87ONm1c3NqUHBRtXWdDJfKKt7vKWFyEZE4570lrNODdJ1rHlHTk8167bZf8Di8kZSsoHnhk6m0kZ8fnymImjROc/Z/641zjupTXCDFqEp3iQ9Cmc/byoAlWyeZpUhJE=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR08MB4128
Original-Authentication-Results: mit.edu; dkim=none (message not signed) header.d=none;mit.edu; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM5EUR03FT004.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: 98351e0a-a3ea-4989-f5d8-08d9106e3d41
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: CyFr5O8/yF4sYq6K8HuXbZ6Q1vEko7V8/Vai86eKJHK2YCp61T2nVVMNBO0uyBnURuPUQL37XrH2wGB7WqNpgAc3JtbUksWx8cPABoHuMB1DN0K11P/INxPxvMZ7coZYeP6HjTFuS+43iSpqglzA8l68fxKa9ZpkQVSq9QztCGUJwLtzMwdDoqQzKSGsBBmk/GrkpoI9vRCMFWu0xzZxCtsOLDUtNueYs0Qd6zdoD09Tmh4/AtnLVKLFPB6XDZttKFBOYnJsHWr5UViYhIrfaMTDvqtHZ9oO7ceRaaK5iehQE7qsNu2+iqeVl7uAt2UccDBAnumSUUus5qmYfihE/ebmJQUPlyevn3O3Hamf0WpU9155QS/KnF1nrmgVDX/+SS4Dtq+t9UUoUrLPk9ePE5sh/sh39oX1Dygv4izpeiW/KJw2m66AM67dckIQCUQNgMYV3UYBmkrSl7RhDz0nO/NLkd6TjXaTd8O9AuxH0cVmjNWpgnm1bzcbSNS47lYqrXrpgma1bfl7IdUjfUtOVki1iflKAPO7Tzh0eDmMHx/0qO7ISmk4xK/1VKuTABOHmAIVttZVK6OY+rLYZvnlraeTMI+CphVh3BGNVjWbzeNbuUYrP5fVjzH19/fCK7vfw75kxqyAPkxil2d5RgRulNVjvtLgf+b51sEnQg+BWNl6dgMRWjJYXBZ7jTpLJEExh80qUSVJmNKF5zQXAHim2fTilCrhXDrTsW6MFkD3XWM=
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(346002)(136003)(396003)(376002)(39860400002)(46966006)(36840700001)(8676002)(316002)(55016002)(8936002)(7696005)(81166007)(36860700001)(82310400003)(54906003)(52536014)(2906002)(5660300002)(83380400001)(966005)(4326008)(478600001)(33656002)(9686003)(336012)(356005)(26005)(186003)(47076005)(6506007)(82740400003)(53546011)(86362001)(70586007)(70206006)(450100002)(110136005); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 06 May 2021 09:06:38.5085 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 85cd486b-797d-44ef-ec61-08d9106e41c9
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: AM5EUR03FT004.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR0802MB2526
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/cCPL_TdWvVdddA3BDTztlY7vZ9A>
Subject: Re: [secdir] Secdir last call review of draft-ietf-tls-dtls-connection-id-11
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 May 2021 09:06:48 -0000

Hi Ben, Hi Daniel,

There is currently a call for adoption of draft-tschofenig-tls-dtls-rrc because the TLS group decided earlier to consider adoption after the completion of draft-ietf-tls-dtls-connection-id-11 & DTLS 1.3 given that there are application specific mechanisms than can provide the same functionality. Of course, as Daniel mentioned below, there are preferences in the design of communication security that play a role here. In the IETF IoT community we have seen folks who prefer to do things at the application layer (CoAP in particular) and then there are folks who want to design a solution as low in the stack as possible.

In any case, we have implemented the 1.2 CID solution and use application layer RRCs. As a co-author of the - dtls-rrc I also want to see a generic solution at the DTLS layer.

Ciao
Hannes


-----Original Message-----
From: secdir <secdir-bounces@ietf.org> On Behalf Of Benjamin Kaduk
Sent: Sunday, May 2, 2021 6:36 AM
To: Daniel Franke <dafranke@akamai.com>
Cc: draft-ietf-tls-dtls-connection-id.all@ietf.org; secdir@ietf.org
Subject: Re: [secdir] Secdir last call review of draft-ietf-tls-dtls-connection-id-11

Hi Daniel,

Thanks for the review.

There was some effort towards a return-routability check at the DTLS layer, in draft-tschofenig-tls-dtls-rrc, but we seem to have failed to follow up after the adoption call was issued.

I've pinged the chairs to check on its progress.

-Ben

On Thu, Apr 22, 2021 at 08:36:56AM -0700, Daniel Franke via Datatracker wrote:
> Reviewer: Daniel Franke
> Review result: Ready
>
> I have reviewed this document as part of the security directorate's
> ongoing effort to review all IETF documents being processed by the
> IESG.  These comments were written primarily for the benefit of the security area directors.
>  Document editors and WG chairs should treat these comments just like
> any other last call comments.
>
> Apologies for the absolute last-minute review; I overlooked until just
> now that this had been assigned a telechat date.
>
> This document is Ready. I do have some concerns — in particular I
> think relying on application-layer measures to prevent amplified
> reflection attacks is a bit dubious — but these have been debated to
> death already, the issues are well-captured in the document, and I don't think I have anything new to add.
>
>

_______________________________________________
secdir mailing list
secdir@ietf.org
https://www.ietf.org/mailman/listinfo/secdir
wiki: http://tools.ietf.org/area/sec/trac/wiki/SecDirReview
IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.