Re: [Tzdist] Stephen Farrell's No Objection on draft-ietf-tzdist-caldav-timezone-ref-04: (with COMMENT)

Cyrus Daboo <cyrus@daboo.name> Thu, 08 October 2015 19:15 UTC

Return-Path: <cyrus@daboo.name>
X-Original-To: tzdist@ietfa.amsl.com
Delivered-To: tzdist@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0C00A1AC3CB; Thu, 8 Oct 2015 12:15:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.912
X-Spam-Level:
X-Spam-Status: No, score=-1.912 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Xc07QvVpJKNr; Thu, 8 Oct 2015 12:15:08 -0700 (PDT)
Received: from daboo.name (daboo.name [173.13.55.49]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 73C601AC3DC; Thu, 8 Oct 2015 12:15:08 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by daboo.name (Postfix) with ESMTP id B72B7215732C; Thu, 8 Oct 2015 15:15:07 -0400 (EDT)
X-Virus-Scanned: amavisd-new at example.com
Received: from daboo.name ([127.0.0.1]) by localhost (daboo.name [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YcGj7jQmxCnB; Thu, 8 Oct 2015 15:15:07 -0400 (EDT)
Received: from [17.45.162.214] (unknown [17.45.162.214]) by daboo.name (Postfix) with ESMTPSA id B7873215731B; Thu, 8 Oct 2015 15:15:05 -0400 (EDT)
Date: Thu, 08 Oct 2015 15:15:04 -0400
From: Cyrus Daboo <cyrus@daboo.name>
To: "Eliot Lear (elear)" <elear@cisco.com>
Message-ID: <3784B46313DEFE0120E67C17@cyrus.local>
In-Reply-To: <3CB0B80A-49C3-4B2A-B32D-BB5DBB650C26@cisco.com>
References: <20150930135935.9433.76218.idtracker@ietfa.amsl.com> ,<31C472AFF9FCDED2E9D8A031@cyrus.local> <3CB0B80A-49C3-4B2A-B32D-BB5DBB650C26@cisco.com>
X-Mailer: Mulberry/4.1.0b1 (Mac OS X)
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline; size="743"
Archived-At: <http://mailarchive.ietf.org/arch/msg/tzdist/9A6KMp_SiRJrjvU_HanErGPKZIA>
Cc: draft-ietf-tzdist-caldav-timezone-ref.shepherd@ietf.org, tzdist@ietf.org, draft-ietf-tzdist-caldav-timezone-ref.ad@ietf.org, The IESG <iesg@ietf.org>, Stephen Farrell <stephen.farrell@cs.tcd.ie>, draft-ietf-tzdist-caldav-timezone-ref@ietf.org, tzdist-chairs@ietf.org
Subject: Re: [Tzdist] Stephen Farrell's No Objection on draft-ietf-tzdist-caldav-timezone-ref-04: (with COMMENT)
X-BeenThere: tzdist@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <tzdist.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tzdist>, <mailto:tzdist-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tzdist/>
List-Post: <mailto:tzdist@ietf.org>
List-Help: <mailto:tzdist-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tzdist>, <mailto:tzdist-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Oct 2015 19:15:12 -0000

Hi Eliot,

--On October 8, 2015 at 7:03:58 PM +0000 "Eliot Lear (elear)" 
<elear@cisco.com> wrote:

> Thanks Cyrus. A mention of the threat that Stephen mentions and then a
> reference should do, then. No?

OK, how about I add this (based on the text Stephen suggested) to the end 
of the Privacy section:

   Note that
   this specification extends the potential privacy issues discussed in
   [I-D.ietf-tzdist-service] since events can be delivered to a calendar
   user from an outside source (e.g., using iTIP [RFC5546]), and an
   attacker could create a calendar event with, e.g., a fake or lesser-
   used time zone identifier, that could be used to monitor the calendar
   user's activity and interaction with others.

-- 
Cyrus Daboo