Re: [Tcpcrypt] v3 of the charter

Stephen Farrell <stephen.farrell@cs.tcd.ie> Wed, 30 April 2014 09:02 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: tcpcrypt@ietfa.amsl.com
Delivered-To: tcpcrypt@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D3A601A08B0 for <tcpcrypt@ietfa.amsl.com>; Wed, 30 Apr 2014 02:02:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.551
X-Spam-Level:
X-Spam-Status: No, score=-2.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p6SXTV0TcftY for <tcpcrypt@ietfa.amsl.com>; Wed, 30 Apr 2014 02:02:07 -0700 (PDT)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) by ietfa.amsl.com (Postfix) with ESMTP id 2838B1A076B for <tcpcrypt@ietf.org>; Wed, 30 Apr 2014 02:02:07 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 7F005BE68; Wed, 30 Apr 2014 10:02:05 +0100 (IST)
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id adfgfoEVD6eO; Wed, 30 Apr 2014 10:02:05 +0100 (IST)
Received: from [134.226.36.180] (stephen-think.dsg.cs.tcd.ie [134.226.36.180]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id 58A12BE58; Wed, 30 Apr 2014 10:02:05 +0100 (IST)
Message-ID: <5360BC0C.3020303@cs.tcd.ie>
Date: Wed, 30 Apr 2014 10:02:04 +0100
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.4.0
MIME-Version: 1.0
To: "Eggert, Lars" <lars@netapp.com>, Marcelo Bagnulo <marcelo@it.uc3m.es>
References: <536099A0.30900@it.uc3m.es> <23862F2E-9D56-4651-9202-FC676D15720B@netapp.com> <5360B4B1.90106@it.uc3m.es> <22212FB9-B128-4EE9-8549-54685A33E461@netapp.com>
In-Reply-To: <22212FB9-B128-4EE9-8549-54685A33E461@netapp.com>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/tcpcrypt/1spKi-f81CHQJcK52GUxZd1Y-E0
Cc: "tcpcrypt@ietf.org" <tcpcrypt@ietf.org>
Subject: Re: [Tcpcrypt] v3 of the charter
X-BeenThere: tcpcrypt@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussion list for adding encryption to TCP." <tcpcrypt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tcpcrypt>, <mailto:tcpcrypt-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tcpcrypt/>
List-Post: <mailto:tcpcrypt@ietf.org>
List-Help: <mailto:tcpcrypt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tcpcrypt>, <mailto:tcpcrypt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Apr 2014 09:02:14 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Overall I think this charter (modulo wordsmithing such as
suggested by Lars) is good enough.

My own nit, but not suggesting a change...

On 30/04/14 09:41, Eggert, Lars wrote:
> Makes sense. Suggest to express it this way, e.g., "the protocol 
> extension must not increase the possibility for endpoint 
> fingerprinting compared to what is possible already".

I generally dislike when a security goal is set to be "no
worse than today" since I think that's how we got e.g. WEP.
But in this case (fingerprinting), I don't think we yet
understand it well enough to do much better. It'd be good
if we did though. So the text Lars suggests is ok.

S.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBAgAGBQJTYLwGAAoJEC88hzaAX42iNwgIAL12XxhpMHfTiYM6Q3R7MFRA
MYqFvEPqwwQe4dJNjjVrkNHYImFKAVtTrV2AB3+vGbr1eUJsC8sGOMsL2m7bgI1e
nUzYUVz93gdQLiUcUP5fwtdfNyXdBIEK6RspfCghi0kSBO+wBZhz2wo669Mj0J5O
6YEx+iorX4Fcyz1PutNchOFCiMabWtd1devZb2QpK5lYzuEzixE/vPWqkwJisD0A
TB5b7vAwxvSJtTxGKK//HASpVCORGsXOAOe8HcSm/UrRKvpqzIT+10vCeslwR//f
I6V+Jdswo0t0okJK4SuxVjV56eT3Dc8pRAgoS4ptR1z+djtyD/veHz6O2s8pRm0=
=Mw5p
-----END PGP SIGNATURE-----