Re: [T2TRG] draft-irtf-t2trg-iot-seccons-07

Hannes Tschofenig <hannes.tschofenig@gmx.net> Thu, 12 October 2017 14:30 UTC

Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: t2trg@ietfa.amsl.com
Delivered-To: t2trg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF97013430F for <t2trg@ietfa.amsl.com>; Thu, 12 Oct 2017 07:30:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.119
X-Spam-Level:
X-Spam-Status: No, score=-2.119 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5jod1XCsmq0J for <t2trg@ietfa.amsl.com>; Thu, 12 Oct 2017 07:30:53 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 52DA4132A1A for <T2TRG@irtf.org>; Thu, 12 Oct 2017 07:30:53 -0700 (PDT)
Received: from [192.168.91.203] ([80.92.116.99]) by mail.gmx.com (mrgmx003 [212.227.17.190]) with ESMTPSA (Nemesis) id 0LgqQQ-1dWHuB2JlO-00oE2Y; Thu, 12 Oct 2017 16:30:49 +0200
To: Ari Keränen <ari.keranen@ericsson.com>, Mohit Sethi M <mohit.m.sethi@ericsson.com>, "T2TRG@irtf.org" <T2TRG@irtf.org>
References: <087c0a89-01d7-9e2c-3c73-342ee5ffd9fe@gmx.net> <08D47E53-2586-49F9-AE12-6113A52B0427@ericsson.com> <87fcf2ba-d02b-75d2-d6b8-cc469819ec7d@ericsson.com> <03EF2523-680F-49A6-A532-167DFAC2F7DE@ericsson.com>
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <2d8023d9-8660-2de0-a332-371aea69ca8c@gmx.net>
Date: Thu, 12 Oct 2017 16:30:48 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.3.0
MIME-Version: 1.0
In-Reply-To: <03EF2523-680F-49A6-A532-167DFAC2F7DE@ericsson.com>
Content-Type: text/plain; charset="utf-8"
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-Provags-ID: V03:K0:IyyyRgKPyT11R+1eZ5YQlKWqH/onpZwipycTGVvh5+5fj//GUK0 cinRNN2ceA2OFzLdG0eyoiug/blC8Dnf6JW4vwE9kc8f3Ue11juVt7/mWtd3Bsy2tpNERPL uCWqv86t6pGZSAu3EXoFEWXVhm41WuKHSecxXcU63GtdO/82lSZXi66XDfu9Qe44Gfpr53t PqWESb6rzWWHnrXIsgcJQ==
X-UI-Out-Filterresults: notjunk:1;V01:K0:87Ez5i23BZA=:ZG5woQ6wY3QkK3WMx3WB6S W3ZdcI/o/m2FGXUfMUvoXZ+P2JWFpU2i0bOz7VgsbSzl3KfG+5hs1R2GqrEyPYVQRdHtw/i4I ZfWZ9s05+zUN/s3ACDYvJLEk/SlRDSspHIPAmU97yLFa1qEKoiAptzadez0eEIt22ZMpawelD 4iJFXgmMjb7JpZ2Oxl8dGHiy7Z1zyic+/OKAKi5eCEGF8K74KWDWLC5NkVsjeZLaS6pl88JUT YnF5A+FI+0x2VwWUQtnj3le86/TcBQ4pV6JtBsXwUEZN6+dUSCKIeBPbmpqecMIaxLyS0D9GH q3iVu9mfJicwzKQ65T2HVYCuyYccfPRJMag/B7NsV1dlBeVNxxA0xm+zVhxAUG6TDIbNHAPiX uSPqqlFnWLnaS/As1IIFv/ajgeONg/avx4LiWdOz0UW29ORTOw+jNxX1yVEwv2FJArxV9YR4n pyngqMtfgjBCEgLrOjmQTzsk0/vz3ALLgsgQZZ13Gh9jebz6e58yFMD2hEKvX/xW5mKClBoMu bnvuMkm5Hk05q1Zp27lN39DzaJihDInWLU7dclRGMhuSL7OUrvww0ATLb3BGJ+gOxuMNZUwCu 8ag8JLrOgWPVkWPMIdUpz9bOQiWC43oMUcNrlSIEOmcIvAGVHZfCcc20Lr0k8eHidm+Flqm7E Ho7zhf9KFNgWfglhs1SEoDOn2zv820eaWwq3wNp8YV+29FD2VrzQMkyJgZtgLFQoQLv0KXO6g 9/O7hm3KyS5bWuzTtoh7JT1le/A+NISWkikozILQ9LEP23b8ibsNvd6r4Btn3LR2B+DCwfDWZ MO97T686g0LiTXT/7qYsbANR9EqMvf4cI4r/wKmU5C3nSozPtg=
Archived-At: <https://mailarchive.ietf.org/arch/msg/t2trg/XtLZtlswsAr2nu3o4sfqvIJVBeE>
Subject: Re: [T2TRG] draft-irtf-t2trg-iot-seccons-07
X-BeenThere: t2trg@irtf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IRTF Thing-to-Thing Research Group <t2trg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/t2trg>, <mailto:t2trg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/t2trg/>
List-Post: <mailto:t2trg@irtf.org>
List-Help: <mailto:t2trg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/t2trg>, <mailto:t2trg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Oct 2017 14:30:56 -0000

Sounds good. I would keep it focused on protocols.

On 10/12/2017 04:26 PM, Ari Keränen wrote:
> Hi,
> 
> I had a fresh look at the draft thinking how we could address the issue of being more clear on the intent(s) of the document. Perhaps we could add to the abstract and/or intro something along the lines of:
> 
> "This document can be used by IoT standards specifications as a reference for details about security considerations applying to the specified system or protocol."
> 
> 
> Cheers,
> Ari
> 
>> On 11 Oct 2017, at 17.58, Mohit Sethi M <mohit.m.sethi@ericsson.com> wrote:
>>
>> Hi Hannes,
>>
>> Thanks for volunteering to shepherd the document. I think your feedback will definitely help the us (the authors) to improve the document quality.
>>
>> I think Ari has very succinctly pointed out the motivation for this draft. Of course, if you think that there is some text that would better highlight the motivation, we are happy to add/modify.
>>
>> Please also bear in mind that this is a informational research group document so it talks about several security challenges, protocols, tools and building blocks.
>>
>> --Mohit
>> On 10/10/2017 02:19 PM, Ari Keränen wrote:
>>> Hi,
>>>
>>> For context on this discussion, as I said in the other thread:
>>>
>>>> This draft started as a "IoT security considerations" document that would allow people writing security considerations for (IETF) IoT drafts to point to more detailed discussion on what are the threats and potential remedies in the envisioned IoT systems. And it still serves that purpose.
>>>>
>>>> In addition the draft summarises the existing work in this space. Hence is turned out to be (also) "SotA and Challenges" draft.
>>> And that's how I read the current text. But yes, let's make sure we are aligned here and the intention is clear for everyone.
>>>
>>>
>>> Cheers,
>>> Ari
>>>
>>>> On 10 Oct 2017, at 12.40, Hannes Tschofenig <Hannes.Tschofenig@gmx.net> wrote:
>>>>
>>>> Hi all,
>>>>
>>>> as I volunteered to help shepherd the draft I want to do a good job in
>>>> reviewing the work.
>>>>
>>>> It would be good for the authors (and the group) to clearly articulate
>>>> what the main purpose of the draft is. Ari mentioned that the purpose
>>>> was to write a "document that would allow people writing security
>>>> considerations for (IETF) IoT drafts". This is not what the document
>>>> currently says.
>>>>
>>>> Either Ari is wrong about the intended purpose or the text needs to be
>>>> corrected.
>>>>
>>>> Before I provide detailed review comments I prefer to know what it aims
>>>> to accomplish.
>>>>
>>>> Ciao
>>>> Hannes
>>>>
>>>> _______________________________________________
>>>> T2TRG mailing list
>>>> T2TRG@irtf.org
>>>> https://www.irtf.org/mailman/listinfo/t2trg
>>> _______________________________________________
>>> T2TRG mailing list
>>> T2TRG@irtf.org
>>> https://www.irtf.org/mailman/listinfo/t2trg
>>
> 
> _______________________________________________
> T2TRG mailing list
> T2TRG@irtf.org
> https://www.irtf.org/mailman/listinfo/t2trg
>