Re: [Simple] New draft on trust_path_discovery

Jonathan Rosenberg <jdrosen@cisco.com> Mon, 25 July 2005 21:28 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DxAVB-0006kt-5i; Mon, 25 Jul 2005 17:28:45 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DxAV9-0006jn-0r for simple@megatron.ietf.org; Mon, 25 Jul 2005 17:28:43 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA25160 for <simple@ietf.org>; Mon, 25 Jul 2005 17:28:37 -0400 (EDT)
Received: from rtp-iport-1.cisco.com ([64.102.122.148]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1DxB00-0000tJ-75 for simple@ietf.org; Mon, 25 Jul 2005 18:00:37 -0400
Received: from rtp-core-2.cisco.com (64.102.124.13) by rtp-iport-1.cisco.com with ESMTP; 25 Jul 2005 14:28:29 -0700
X-BrightmailFiltered: true
X-Brightmail-Tracker: AAAAAA==
X-IronPort-AV: i="3.95,140,1120460400"; d="scan'208"; a="3322367:sNHT22637568"
Received: from xbh-rtp-201.amer.cisco.com (xbh-rtp-201.cisco.com [64.102.31.12]) by rtp-core-2.cisco.com (8.12.10/8.12.6) with ESMTP id j6PLSSVu005665; Mon, 25 Jul 2005 17:28:29 -0400 (EDT)
Received: from xfe-rtp-201.amer.cisco.com ([64.102.31.38]) by xbh-rtp-201.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.211); Mon, 25 Jul 2005 17:28:35 -0400
Received: from [192.168.1.100] ([10.86.242.189]) by xfe-rtp-201.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.211); Mon, 25 Jul 2005 17:28:39 -0400
Message-ID: <42E5597B.8030003@cisco.com>
Date: Mon, 25 Jul 2005 17:28:27 -0400
From: Jonathan Rosenberg <jdrosen@cisco.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7.8) Gecko/20050511
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: Kumiko Ono <ono.kumiko@lab.ntt.co.jp>
Subject: Re: [Simple] New draft on trust_path_discovery
References: <B0C588289108FAono.kumiko@lab.ntt.co.jp>
In-Reply-To: <B0C588289108FAono.kumiko@lab.ntt.co.jp>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
X-OriginalArrivalTime: 25 Jul 2005 21:28:39.0911 (UTC) FILETIME=[D3135F70:01C5915F]
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 31247fb3be228bb596db9127becad0bc
Content-Transfer-Encoding: 7bit
Cc: kumiko@cs.columbia.edu, simple@ietf.org, Henning Schulzrinne <hgs@cs.columbia.edu>
X-BeenThere: simple@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: SIP for Instant Messaging and Presence Leveraging Extensions <simple.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/simple>, <mailto:simple-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/simple>
List-Post: <mailto:simple@ietf.org>
List-Help: <mailto:simple-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/simple>, <mailto:simple-request@ietf.org?subject=subscribe>
Sender: simple-bounces@ietf.org
Errors-To: simple-bounces@ietf.org

This is a very interesting draft. This kind of presence-based reputation 
system is definitely a strong contender for a piece of the anti-spam 
puzzle.

Building a protocol to do this is very challenging. One of the design 
decisions is whether or not it is pushed based, akin to a vector routing 
protocl (as you have proposed) or whether it is query-based. I am 
concerned that a push-based routing protocol type of solution is simply 
not going to scale, as the level of aggregation will not be sufficient. 
Though there is a form of aggregation, in terms of combining paths to 
the same recipient, there is no way to aggregate decisions across 
recipients. The latter is analagous to combining prefixes in BGP, and 
that is not possible here since the identifiers are from a flat namespace.

Furthermore, I may not want to reveal all of my trust relationships to 
everyone, indeed, I may not want to reveal the same trust relationships 
to different people. Consider this example. I have a buddy list with 
lots of buddies on it. Those buddies include colleagues from work, 
family, and certain business associates that I deal with, but 
confidentially (example: the business development manager from a company 
about to acquire my company). I don't want everyone I trust to actually 
know that I trust this biz dev guy, since that reveals confidential 
information.

Because of this, I think that these trust chains need to be query based. 
Indeed, care must be taken to make sure the privacy issues I mention 
above can be dealt with. Indeed, if you allow transitive queries - user 
A queries B that queries C, it can get really hard to preserve the 
privacy needed.

Thanks,
Jonathan R.


Kumiko Ono wrote:

> Hi all,
> 
> Henning and I wrote up the I-D that proposes a mechanism to find friends
> -of-friends and trusted domains, which could be used as a tool to 
> protect users from spam/spit. We could not find any WG that this draft 
> should belong to, but we believe the SIPPING/SIMPLE WG might be 
> interested in this draft. Any comments are welcome.
> 
> 
> 
>>	Title		: Trust Path Discovery
>>	Author(s)	: K. Ono, H. Schulzrinne
>>	Filename	: draft-ono-trust-path-discovery-00.txt
>>	Pages		: 14
>>	Date		: 2005-7-12
>>	
>>  Chained or transitive trust can be used to determine whether incoming
>>  communication is likely to be desirable or not.  We can build a
>>  chained trust relationship by introducing friends to out friends, for
>>  example.  We propose mechanisms for discovering trust paths and
>>  binary responsive trustworthiness.  The trust paths are based on a
>>  chain of trust relationships between users, a user and a domain, and
>>  domains.  We apply this model to relatively low-value trust
>>  establishment, suitable for deciding whether to accept communication
>>  requests such as emails, calls, or instant messages from strangers.
>>
>>A URL for this Internet-Draft is:
>>http://www.ietf.org/internet-drafts/draft-ono-trust-path-discovery-00.txt
> 
> 
> Thanks,
> Kumiko
> 
> 
> _______________________________________________
> Simple mailing list
> Simple@ietf.org
> https://www1.ietf.org/mailman/listinfo/simple
> 

-- 
Jonathan D. Rosenberg, Ph.D.                   600 Lanidex Plaza
Director, Service Provider VoIP Architecture   Parsippany, NJ 07054-2711
Cisco Systems
jdrosen@cisco.com                              FAX:   (973) 952-5050
http://www.jdrosen.net                         PHONE: (973) 952-5000
http://www.cisco.com

_______________________________________________
Simple mailing list
Simple@ietf.org
https://www1.ietf.org/mailman/listinfo/simple