Re: [tsvwg] I-D Action: draft-ietf-tsvwg-transport-encrypt-04.txt

Gorry Fairhurst <gorry@erg.abdn.ac.uk> Tue, 19 February 2019 17:40 UTC

Return-Path: <gorry@erg.abdn.ac.uk>
X-Original-To: tsvwg@ietfa.amsl.com
Delivered-To: tsvwg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7D6E6130F44 for <tsvwg@ietfa.amsl.com>; Tue, 19 Feb 2019 09:40:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U0efrV5YUroZ for <tsvwg@ietfa.amsl.com>; Tue, 19 Feb 2019 09:40:48 -0800 (PST)
Received: from pegasus.erg.abdn.ac.uk (pegasus.erg.abdn.ac.uk [137.50.19.135]) by ietfa.amsl.com (Postfix) with ESMTP id D0403130F2A for <tsvwg@ietf.org>; Tue, 19 Feb 2019 09:40:47 -0800 (PST)
Received: from Gs-MacBook-Pro.local (fgrpf.plus.com [212.159.18.54]) by pegasus.erg.abdn.ac.uk (Postfix) with ESMTPSA id 62B5C1B00244; Tue, 19 Feb 2019 17:40:44 +0000 (GMT)
Message-ID: <5C6C3F9C.1070601@erg.abdn.ac.uk>
Date: Tue, 19 Feb 2019 17:40:44 +0000
From: Gorry Fairhurst <gorry@erg.abdn.ac.uk>
Reply-To: gorry@erg.abdn.ac.uk
Organization: University of Aberdeen
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:12.0) Gecko/20120428 Thunderbird/12.0.1
MIME-Version: 1.0
To: Tom Herbert <tom@herbertland.com>
CC: tsvwg <tsvwg@ietf.org>
References: <155052226474.25978.1700439564007128149@ietfa.amsl.com> <CALx6S34o08DY-v-1S59VAerwpnf3wD6puNGe-Jq90aswYdK8Xw@mail.gmail.com>
In-Reply-To: <CALx6S34o08DY-v-1S59VAerwpnf3wD6puNGe-Jq90aswYdK8Xw@mail.gmail.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/tsvwg/e2Q8kDuHgYlfMxyBZhc8F_-r8Sk>
Subject: Re: [tsvwg] I-D Action: draft-ietf-tsvwg-transport-encrypt-04.txt
X-BeenThere: tsvwg@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Transport Area Working Group <tsvwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tsvwg>, <mailto:tsvwg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tsvwg/>
List-Post: <mailto:tsvwg@ietf.org>
List-Help: <mailto:tsvwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tsvwg>, <mailto:tsvwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Feb 2019 17:40:50 -0000

On 19/02/2019, 17:13, Tom Herbert wrote:
> Hello,
>
> I am still having a hard time believing that need for operators to
> inspect and process transport layer information in ad hoc ways
> remotely outweighs the need for users' security and privacy and to
> impede protocol ossification.
Whatever you c
> Regardless of the arguments in the
> draft, I believe that the trend will be more use of encryption even in
> the transport layer.
That certainly is the way it looks, to summarise the draft says:
"

    As seen, different transports use encryption to protect their header
    information to varying degrees.  There is, however, a trend towards
    increased protection with newer transport protocols.

"
> Consequently, it would be nice if the draft had
> more discussion about alternative means for network devices to get the
> information about the transport layer that they need.
Our guidance on scoping means that we can include deployed methods, are 
there examples that you can tell us about?
> In particular, I
> still think possibility of using extension headers is far too easily
> dismissed by the draft (please see my previous comments about that).
I also think there may be potential here in future, and would love to 
see this area explored - it is a topic in which I have research, and I 
believe you also. I can't however point yet to deployment examples in 
this area. Do you know more?

Gorry
> Tom
>
> On Mon, Feb 18, 2019 at 12:38 PM<internet-drafts@ietf.org>  wrote:
>>
>> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>> This draft is a work item of the Transport Area Working Group WG of the IETF.
>>
>>          Title           : The Impact of Transport Header Confidentiality on Network Operation and Evolution of the Internet
>>          Authors         : Godred Fairhurst
>>                            Colin Perkins
>>          Filename        : draft-ietf-tsvwg-transport-encrypt-04.txt
>>          Pages           : 43
>>          Date            : 2019-02-18
>>
>> Abstract:
>>     This document describes implications of applying end-to-end
>>     encryption at the transport layer.  It identifies in-network uses of
>>     transport layer header information.  It then reviews the implications
>>     of developing end-to-end transport protocols that use authentication
>>     to protect the integrity of transport information or encryption to
>>     provide confidentiality of the transport protocol header and expected
>>     implications of transport protocol design and network operation.
>>     Since transport measurement and analysis of the impact of network
>>     characteristics have been important to the design of current
>>     transport protocols, it also considers the impact on transport and
>>     application evolution.
>>
>>
>> The IETF datatracker status page for this draft is:
>> https://datatracker.ietf.org/doc/draft-ietf-tsvwg-transport-encrypt/
>>
>> There are also htmlized versions available at:
>> https://tools.ietf.org/html/draft-ietf-tsvwg-transport-encrypt-04
>> https://datatracker.ietf.org/doc/html/draft-ietf-tsvwg-transport-encrypt-04
>>
>> A diff from the previous version is available at:
>> https://www.ietf.org/rfcdiff?url2=draft-ietf-tsvwg-transport-encrypt-04
>>
>>
>> Please note that it may take a couple of minutes from the time of submission
>> until the htmlized version and diff are available at tools.ietf.org.
>>
>> Internet-Drafts are also available by anonymous FTP at:
>> ftp://ftp.ietf.org/internet-drafts/
>>