Re: [secdir] New Routing Area Security Design Team

Richard Barnes <rlb@ipv.sx> Fri, 13 April 2018 20:21 UTC

Return-Path: <rlb@ipv.sx>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9CFE212946D for <secdir@ietfa.amsl.com>; Fri, 13 Apr 2018 13:21:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.609
X-Spam-Level:
X-Spam-Status: No, score=-2.609 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, T_DKIMWL_WL_MED=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AMzVpXIKe4Gn for <secdir@ietfa.amsl.com>; Fri, 13 Apr 2018 13:20:57 -0700 (PDT)
Received: from mail-oi0-x22d.google.com (mail-oi0-x22d.google.com [IPv6:2607:f8b0:4003:c06::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5561C127978 for <secdir@ietf.org>; Fri, 13 Apr 2018 13:20:57 -0700 (PDT)
Received: by mail-oi0-x22d.google.com with SMTP id u84-v6so9474682oie.10 for <secdir@ietf.org>; Fri, 13 Apr 2018 13:20:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=wYVp8teNfbphqk6s09Cm088UuJXpHnpnPp02xznmG60=; b=NXAF0lvwxYPk//BfWNxaxsOvWRQuc5TPW36vSsuEfBa5sBojtDTnyFLt0tfAcSoZ2B E/HwX2NYTT8c79uSeV2sbY6mefdX7SnmWBNHUiPZ6NOiIIO4VDv3796SzAUt/o7/PtPI s+eyELMp7G/YcxhFOGZCs5o1Sh4nBttw4R8hw90WTW3uaVPkob/t2RCtGXpgC0mUHwAT mC3Z5KNQ7yNUO5ukW70mmg1DZvz8xwn9snCwIt6suniFXGLBksnqGIi1/5EpJGoKnw99 wLMze9RQuwOnD9MXDK/yzNxmfTdOukTRPljWMekq6wjgdQyZfIwnLJQWCd6folwZ7AVp dq2Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=wYVp8teNfbphqk6s09Cm088UuJXpHnpnPp02xznmG60=; b=ZG3PcKGpIpaxDkV2n7t09XvKFTx8KCjTJT7aP0t+g30v2W/2/D/MZx9yTybQ9I0RQx BYvoDHPuVQRxuxrjV1Ta4CmztX082lNiN0BiPj7Xjo9gk29CcoGVgtel+5ysF+rwA2Rg 29MS2/UUqpuX2hLklGDWil1Zyw+BFdVwt+bbcie2DVLPZaakdcKHPrjpnkWnrRdVhEn2 XzSr+cwac7Nm6HEZF9zhKwmg+XCIV3aRPmH+FFh8Nh833/WQizeLPtkv+4wUZ5BjJ3gU zN/7++VA2VJojDKM0SCoZFyU2cCIjkE72LnoR8Pw6PaE63D4Og0pJU2kyzgkES0wIgNx SwXg==
X-Gm-Message-State: ALQs6tCqchfvhPw1NEdRWV1trwUcK95ALrqDYfYPJqdY/d8Z7jW7BGp5 zQZlv90AHmZSuC8JR2/L844fhqngM+NQerd1rTTANw==
X-Google-Smtp-Source: AIpwx4+pLAwghi0SNi9cFKTJLmcQepRfIvTG/G3s9EyNVkfiLA4NxQyTAqa7QlmyTP7UY9YTk38vMJD1chBBAs+iI4U=
X-Received: by 2002:aca:30c6:: with SMTP id w189-v6mr8894010oiw.29.1523650856524; Fri, 13 Apr 2018 13:20:56 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.201.90.67 with HTTP; Fri, 13 Apr 2018 13:20:56 -0700 (PDT)
In-Reply-To: <F64C10EAA68C8044B33656FA214632C8882C74A7@MISOUT7MSGUSRDE.ITServices.sbc.com>
References: <F64C10EAA68C8044B33656FA214632C8882C74A7@MISOUT7MSGUSRDE.ITServices.sbc.com>
From: Richard Barnes <rlb@ipv.sx>
Date: Fri, 13 Apr 2018 16:20:56 -0400
Message-ID: <CAL02cgS9rZKVtZs4aRWJmaQj-anaSqYj8rn8roDdxP+JhBR++A@mail.gmail.com>
To: "BRUNGARD, DEBORAH A" <db3546@att.com>
Cc: "secdir@ietf.org" <secdir@ietf.org>, "russ@riw.us" <russ@riw.us>, "Jeffrey Haas (jhaas@pfrc.org)" <jhaas@pfrc.org>, "Stewart Bryant (stewart.bryant@gmail.com)" <stewart.bryant@gmail.com>, "Acee Lindem (acee) (acee@cisco.com)" <acee@cisco.com>
Content-Type: multipart/alternative; boundary="00000000000010de750569c09c95"
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/iIHXMv-H6VnjwKjKqhFgSot2grs>
Subject: Re: [secdir] New Routing Area Security Design Team
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Apr 2018 20:21:02 -0000

(trimming the CC list a bit)

Hey Deborah,

Delighted to hear this news.  Do you have an idea of what the initial
deliverables are for this group?  What security problems are they going to
try to address?

TBH, it seems like the headline problem at the Internet level is BGP
abuse.  The base RPKI docs have been out for several years now, and BGPSEC
is pretty much finished, but the deployment numbers continue to hover
around 8-9% for even the most basic protections.  It would be delightful to
have a group take a look at what the deployment blockers are here, and
whether there's anything the IETF could do to help, whether it's updating
protocols, producing deployment guides, writing code, etc.  We shouldn't
think that RFCs are the only tool in our arsenal.

Thanks,
--Richard

[1] https://rpki-monitor.antd.nist.gov/


On Fri, Apr 13, 2018 at 4:11 PM, BRUNGARD, DEBORAH A <db3546@att.com> wrote:

> The Routing ADs have chartered a design team as described below.
>
>
>
> I will be the AD-contact: db3546@att.com
>
>
>
> Routing Area Security Design Team Charter
>
>
>
> Internet security threats have evolved in the last couple of years and
> questions are arising about the security properties of many long-standing
> IETF routing protocols and new protocols under development. This is an
> opportunity for the Routing Area to evaluate current assumptions and make
> recommendations for new work.
>
>
>
> The Routing Area will kick off a Routing Area-wide Design team with
> support from the OPS Area and Security Area. The first phase will consist
> of a small team:
>
>
>
> Stewart Bryant stewart.bryant@gmail.com
>
> Jeff Haas jhaas@pfrc.org
>
> Acee Lindem acee@cisco.com
>
> Russ White russ@riw.us
>
>
>
> They will be responsible to set up an environment (e..g. wiki), identify
> work items, and coordinating overall the work effort. It is the expectation
> this initial phase will be done by May 1. A second phase will consist of
> small teams working on targeted items. Work items will include review of
> current deployments (use models) and threat models, evaluation criteria and
> useful advice when doing new work (on existing protocols and new
> protocols), and recommendations on where new work is needed in cooperation
> with the responsible working group. The work will have support from the
> Security Area and OPS Area.
>
>
>
> The design team will have a private mailing list for this first phase and
> can be reached at rt-dt-security@ietf.org.
>
>
>
> Regards,
>
> Deborah
>
>
>
>
>
> _______________________________________________
> secdir mailing list
> secdir@ietf.org
> https://www.ietf.org/mailman/listinfo/secdir
> wiki: http://tools.ietf.org/area/sec/trac/wiki/SecDirReview
>
>