Re: [therightkey] Impact on issue processes
Chris Palmer <palmer@google.com> Thu, 25 October 2012 23:26 UTC
Return-Path: <palmer@google.com>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E08FF21F88D0 for <therightkey@ietfa.amsl.com>; Thu, 25 Oct 2012 16:26:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.977
X-Spam-Level:
X-Spam-Status: No, score=-102.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3GDTcSPZQw4j for <therightkey@ietfa.amsl.com>; Thu, 25 Oct 2012 16:26:04 -0700 (PDT)
Received: from mail-wg0-f44.google.com (mail-wg0-f44.google.com [74.125.82.44]) by ietfa.amsl.com (Postfix) with ESMTP id 1FA3F21F88CF for <therightkey@ietf.org>; Thu, 25 Oct 2012 16:26:03 -0700 (PDT)
Received: by mail-wg0-f44.google.com with SMTP id dr13so1208298wgb.13 for <therightkey@ietf.org>; Thu, 25 Oct 2012 16:26:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding:x-system-of-record; bh=HqplM/swclSHc8uBLMzh9fM1tPkKqMAusjUlnskNzNw=; b=bsAycqPQYo8WpkrtdMuDxSuS6N9TsoFbcT5VobOoUNiOZhvNRRAbNT1tSd2iQP3NYe kjzf6+a5s7acHB4Cv3LtuxaWwHL1NglPe58+tGkQwAniH66OJw1A3XzH4oo2TO9KrrHF pdGZOEpTyCVU5sVeR0qnlXVxTjhv+SwkFW1Cml6jTfQhoAXd4n6O6E2fY0SYC9PW5omy 37bZBDHGlnVQK6GglUMILIRKVd5hGe5vrOwOp2i3ZLhQqkT2g/rr0amfepcqKOhyIXgz lzYDiv8RaIUZ5Z0C7brbyzMwfR1pF6vyzkNoMm3CpBLv8HaEnl3jiT6qdXqbemtEZJ65 T2fg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding:x-system-of-record :x-gm-message-state; bh=HqplM/swclSHc8uBLMzh9fM1tPkKqMAusjUlnskNzNw=; b=EkMEeRNkqZT202t1DwbRPjaVcVXnfDDTKCzBF/XycLzNRqpEcEiPdaGhEdI+wEgVeH MWMPNj6PZD6/IjD5Ru3ejBPSDfZHhT/OkETPBQ3Pkl0zR15C22+Qz7ippvkL67nrZA1c wAMKmMk9hf2wteE1wDYWRFV40qQ4MkV9yMBxZR9uuF0NZqbFicBXpjtnYVgQP7lsz5zI l9+asoLXV2y3u654uEPcsgzF8t4ANnpdJ73fZOo1SSpbvTcuECWbkTNPl0HVQ7NU5XN0 fsVQydFuF/o8mTE/f4inV3MCW4FqdtpNWk8IpvfZ5tJs+ZPj7t0wSGPp4zcgsla3Ck6q xekw==
MIME-Version: 1.0
Received: by 10.180.102.131 with SMTP id fo3mr902269wib.1.1351207563321; Thu, 25 Oct 2012 16:26:03 -0700 (PDT)
Received: by 10.223.64.199 with HTTP; Thu, 25 Oct 2012 16:26:02 -0700 (PDT)
In-Reply-To: <544B0DD62A64C1448B2DA253C0114146069D5FC685@TUS1XCHEVSPIN33.SYMC.SYMANTEC.COM>
References: <7500672F-5BDE-4EBE-ABC3-1AFEF2972D95@vpnc.org> <70E51AD3-D937-416E-8F3C-60B6156190DC@vpnc.org> <CAMm+LwgSrwBO=cD5zQ5G1PG0YyC7gvG7cWGqhL1KhPectG6Y+w@mail.gmail.com> <DDDF8726-F491-46AB-9A4A-AFB99006A393@vpnc.org> <42F98BCB-17F8-427E-8E9D-33A04978A339@vpnc.org> <CAMm+LwihwHFYcAkJvjRe7Js9AJkS8s6ZooxJnE526UOsWHGCuw@mail.gmail.com> <A09B4DFF-936C-488C-9915-B5F9A579FA1F@vpnc.org> <CABrd9STFeAxxmFDCZMkREXyEcKbeeQbF8ZeESXcoKPnkckdZwQ@mail.gmail.com> <CAMm+Lwg6EoSy-p7US0uZtKjxGHF39iH-0mvxg-hJ+AqK4vXL-A@mail.gmail.com> <CABrd9SRa9Ye9gkjpaQ+PqQyay9NKJB__dkDwOBwPHvw16dkTRg@mail.gmail.com> <544B0DD62A64C1448B2DA253C0114146069D3FBAE8@TUS1XCHEVSPIN33.SYMC.SYMANTEC.COM> <CAOuvq22PMSq2sAmUBfJcWu6LhEdCA3jKteu38m4UuHbykp7xZw@mail.gmail.com> <544B0DD62A64C1448B2DA253C0114146069D5FC685@TUS1XCHEVSPIN33.SYMC.SYMANTEC.COM>
Date: Thu, 25 Oct 2012 16:26:02 -0700
Message-ID: <CAOuvq21Pt0+uJFEJ==Qc=rUAeSEfGpLA=5UKy-_aBJ4bdWi+xg@mail.gmail.com>
From: Chris Palmer <palmer@google.com>
To: Rick Andrews <Rick_Andrews@symantec.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-System-Of-Record: true
X-Gm-Message-State: ALoCoQnN389GCrgnnbE+ogBj4vDi5vZ6QKdy5irhz8HSJotqzVmdIbsYgCZ1eLK+LNsTY9a9InHQOavR0t8sjRekrfcfiamNQTawWHKN2A9xmdLjHT+N7hBOtJblDgiqgrsvUt7AYveNdR5vEwF3ezPSWKDAMlqtljx8KmD8mnnGMfawcJFbpR4G2LfuocDfKNECbR0o+w5A
Cc: Phillip Hallam-Baker <hallam@gmail.com>, "therightkey@ietf.org" <therightkey@ietf.org>, Ben Laurie <benl@google.com>, Paul Hoffman <paul.hoffman@vpnc.org>
Subject: Re: [therightkey] Impact on issue processes
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Oct 2012 23:26:05 -0000
On Thu, Oct 25, 2012 at 3:40 PM, Rick Andrews <Rick_Andrews@symantec.com> wrote: > It's going to cost engineering time and money for CAs to implement CT. The bean counters and execs who control the purse strings are going to ask what they'll get for their $$$. They'll ask "so if I spend this money, we won't get hacked, right?" and I would have to say no, it's no guarantee that we wouldn't get hacked, but if we got hacked we would know about it. And the attackers have much less incentive to hack you. That is a really big win. Obviously the cost is not $0, but the payoff is significant. In a CT world, what does Comodo Hacker gain by causing mis-issuance? It's a looooot less than now. Tell your bean counters that. > CT is *a* solution, but by no means the only possible solution. Is there another solution that might be less expensive and intrusive to implement? CAA might get us 80% of the way there for a fraction of the cost. DANE and cert pinning also help, and might be simpler to implement. Obviously I like key pinning, but I consider CT (or a public log solution generally) as the "true", long-term solution. Pinning would probably continue to be of complementary value, as might DANE/CAA/whatever else. But I consider that CT is where we want to be. And other people are already offering to take on the really big costs. Tell your bean counters that, too: It's a collaborative effort, and other people have already started paying. It might be that all you have to do is implement somebody else's design and talk to somebody else's service (although obviously helping out sooner benefits you too).
- [therightkey] Certrans BoF planning Paul Hoffman
- [therightkey] Call for agenda items for certrans … Paul Hoffman
- Re: [therightkey] Call for agenda items for certr… Phillip Hallam-Baker
- Re: [therightkey] Call for agenda items for certr… Paul Hoffman
- Re: [therightkey] Call for agenda items for certr… Paul Hoffman
- Re: [therightkey] Call for agenda items for certr… Phillip Hallam-Baker
- [therightkey] Impact on issue processes Paul Hoffman
- Re: [therightkey] Impact on issue processes Ben Laurie
- Re: [therightkey] Impact on issue processes Phillip Hallam-Baker
- Re: [therightkey] Impact on issue processes Rob Stradling
- Re: [therightkey] Impact on issue processes Ben Laurie
- Re: [therightkey] Impact on issue processes Ben Laurie
- Re: [therightkey] Impact on issue processes Phillip Hallam-Baker
- Re: [therightkey] Impact on issue processes Erwann Abalea
- Re: [therightkey] Impact on issue processes Rick Andrews
- Re: [therightkey] Impact on issue processes Chris Palmer
- Re: [therightkey] Impact on issue processes Ben Laurie
- Re: [therightkey] Impact on issue processes Paul Hoffman
- Re: [therightkey] Impact on issue processes Phillip Hallam-Baker
- Re: [therightkey] Impact on issue processes Paul Hoffman
- Re: [therightkey] Impact on issue processes Rob Stradling
- Re: [therightkey] Impact on issue processes Paul Hoffman
- Re: [therightkey] Impact on issue processes Rick Andrews
- [therightkey] Other solutions to the problem Paul Hoffman
- Re: [therightkey] Impact on issue processes Chris Palmer
- Re: [therightkey] Other solutions to the problem Rick Andrews
- Re: [therightkey] Other solutions to the problem Chris Palmer
- Re: [therightkey] Other solutions to the problem Yoav Nir
- Re: [therightkey] Other solutions to the problem Rob Stradling
- Re: [therightkey] Other solutions to the problem Ben Laurie
- Re: [therightkey] Impact on issue processes Ben Laurie
- Re: [therightkey] Call for agenda items for certr… Ben Laurie
- Re: [therightkey] Other solutions to the problem Rick Andrews
- Re: [therightkey] Other solutions to the problem Leif Johansson
- Re: [therightkey] Other solutions to the problem Ben Laurie
- Re: [therightkey] Other solutions to the problem Ben Laurie
- Re: [therightkey] Other solutions to the problem Rick Andrews
- Re: [therightkey] Other solutions to the problem Stephen Farrell
- Re: [therightkey] Other solutions to the problem Ben Laurie
- Re: [therightkey] Other solutions to the problem Phillip Hallam-Baker
- Re: [therightkey] Other solutions to the problem Ben Laurie
- [therightkey] Barely-capable CAs Paul Hoffman
- Re: [therightkey] Barely-capable CAs Phillip Hallam-Baker
- Re: [therightkey] Barely-capable CAs Lucy Lynch
- Re: [therightkey] Barely-capable CAs Paul Hoffman
- Re: [therightkey] Barely-capable CAs Rick Andrews
- Re: [therightkey] Barely-capable CAs Phillip Hallam-Baker
- Re: [therightkey] Barely-capable CAs Stephen Farrell
- Re: [therightkey] Barely-capable CAs Paul Hoffman
- Re: [therightkey] Barely-capable CAs Phillip Hallam-Baker
- Re: [therightkey] Barely-capable CAs Ben Laurie
- Re: [therightkey] Barely-capable CAs Phillip Hallam-Baker
- Re: [therightkey] Barely-capable CAs Rob Stradling
- Re: [therightkey] Barely-capable CAs Nico Williams
- Re: [therightkey] Barely-capable CAs Ben Laurie
- Re: [therightkey] Barely-capable CAs Paul Hoffman
- Re: [therightkey] Barely-capable CAs Rob Stradling
- Re: [therightkey] Barely-capable CAs Phillip Hallam-Baker
- Re: [therightkey] Barely-capable CAs Rob Stradling
- Re: [therightkey] Barely-capable CAs Rob Stradling
- Re: [therightkey] Barely-capable CAs Paul Hoffman
- Re: [therightkey] Barely-capable CAs Rob Stradling
- Re: [therightkey] Barely-capable CAs Rob Stradling
- Re: [therightkey] Barely-capable CAs Martin Rex
- Re: [therightkey] Barely-capable CAs Jon Callas
- Re: [therightkey] Barely-capable CAs Jon Callas
- Re: [therightkey] Barely-capable CAs Phillip Hallam-Baker