Re: [Smart] Practical Example

Lars Eggert <lars@eggert.org> Mon, 04 March 2019 07:55 UTC

Return-Path: <lars@eggert.org>
X-Original-To: smart@ietfa.amsl.com
Delivered-To: smart@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2568E130F32 for <smart@ietfa.amsl.com>; Sun, 3 Mar 2019 23:55:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wDENGDB_gltr for <smart@ietfa.amsl.com>; Sun, 3 Mar 2019 23:55:25 -0800 (PST)
Received: from emh06.mail.saunalahti.fi (emh06.mail.saunalahti.fi [62.142.5.116]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 48A8A127598 for <smart@irtf.org>; Sun, 3 Mar 2019 23:55:25 -0800 (PST)
Received: from eggert.org (unknown [62.248.255.8]) by emh06.mail.saunalahti.fi (Postfix) with ESMTP id 9D77230147; Mon, 4 Mar 2019 09:55:22 +0200 (EET)
Received: from slate.eggert.org (pf.eggert.org [172.16.0.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by eggert.org (Postfix) with ESMTPSA id 1FCEB886E61; Mon, 4 Mar 2019 09:55:13 +0200 (EET)
From: Lars Eggert <lars@eggert.org>
Message-Id: <C273D8D6-843E-4160-BC88-AA28F234831E@eggert.org>
Content-Type: multipart/signed; boundary="Apple-Mail=_DB80AE9D-9534-4E32-BE32-A12F2CFEBAD9"; protocol="application/pgp-signature"; micalg="pgp-sha512"
Mime-Version: 1.0 (Mac OS X Mail 12.2 \(3445.102.3\))
Date: Mon, 04 Mar 2019 09:55:12 +0200
In-Reply-To: <487EFB0F-83D8-49CF-BF6A-DFB3A023A641@gmail.com>
Cc: smart@irtf.org
To: Bret Jordan <jordan.ietf@gmail.com>
References: <487EFB0F-83D8-49CF-BF6A-DFB3A023A641@gmail.com>
X-Mailer: Apple Mail (2.3445.102.3)
X-MailScanner-ID: 1FCEB886E61.A7D3C
X-MailScanner: Found to be clean
X-MailScanner-From: lars@eggert.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/smart/aqVFr46yOp5mzveF9DOFra3icAY>
Subject: Re: [Smart] Practical Example
X-BeenThere: smart@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Stopping Malware And Researching Threats <smart.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/smart>, <mailto:smart-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smart/>
List-Post: <mailto:smart@irtf.org>
List-Help: <mailto:smart-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/smart>, <mailto:smart-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Mar 2019 07:55:27 -0000

Hi,

On 2019-3-3, at 19:48, Bret Jordan <jordan.ietf@gmail.com> wrote:
> 2) No, I am not going to release my toolkits or frameworks publicly
> 
> 3) No, I will not discuss these attacks and exploits over public archived channels. Yes, threat actors do monitor lists like this one.

so, I guess we're done then?

Sorry for the flippant response, but the IETF and IRTF are all about discussing issues openly. If that approach isn't feasible, there isn't really much else we can engage over.

Lars