Re: [Tzdist] AD review of draft-ietf-tzdist-service-07 - Sections 8 - 10

Mike Douglass <mikeadouglass@gmail.com> Tue, 12 May 2015 18:27 UTC

Return-Path: <mikeadouglass@gmail.com>
X-Original-To: tzdist@ietfa.amsl.com
Delivered-To: tzdist@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 019C01ACE72 for <tzdist@ietfa.amsl.com>; Tue, 12 May 2015 11:27:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Q1HnaacFKkmi for <tzdist@ietfa.amsl.com>; Tue, 12 May 2015 11:27:03 -0700 (PDT)
Received: from mail-qg0-x22d.google.com (mail-qg0-x22d.google.com [IPv6:2607:f8b0:400d:c04::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 406551ACE31 for <tzdist@ietf.org>; Tue, 12 May 2015 11:27:03 -0700 (PDT)
Received: by qgeb100 with SMTP id b100so8961374qge.3 for <tzdist@ietf.org>; Tue, 12 May 2015 11:27:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type:content-transfer-encoding; bh=PwV13MMBKeAe0cJXRLDE+7iadM9V3YjW/n5Bux8SkFE=; b=eDXCt/ZEvFkGZKM1aQicAUxsulziyRU5GOR0NFFMsNuT7k9B6qP6H/j6zWJdPgFPfD I+G69ghghkfgEF5e8G7/W7S3gdLfxJ5FxqOvKUNNzvsbPFgVGa2qZfSLwF6iCbOq9Nte twsK9Ty8/ltUVJt0FxXqdctmI2lL+3WP/LUM0iHU8TcXt7xDAChKX4QzOqldMzNThO+z dLToxA3P89/GwDR+cJ3uxR9ll9ifnq7JsodU45Gnh+wHTfrErk9lqO0wtovcr07GcZ7a cp1XCgK/elUPxDpjsS7iOxxlAddRTtPHd0NEu96ROuuT82hpfRaWeP1XryGmCmvF6Zm1 hGyA==
X-Received: by 10.140.18.205 with SMTP id 71mr21410935qgf.101.1431455222472; Tue, 12 May 2015 11:27:02 -0700 (PDT)
Received: from ?IPv6:2620:0:2820:2:ad70:8433:fed0:ab13? ([2620:0:2820:2:ad70:8433:fed0:ab13]) by mx.google.com with ESMTPSA id e5sm13764516qkh.19.2015.05.12.11.27.01 for <tzdist@ietf.org> (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 12 May 2015 11:27:01 -0700 (PDT)
Message-ID: <555245F3.4040201@gmail.com>
Date: Tue, 12 May 2015 14:26:59 -0400
From: Mike Douglass <mikeadouglass@gmail.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: tzdist@ietf.org
References: <CALaySJKUcgkMNsFPk0X6ur-Fw0LrB0-miQvAKYJD2rMCEFpBSQ@mail.gmail.com> <88871A9AF67EF351387A3BBF@cyrus.local> <CALaySJLtkDjzeiqDvrAj2e0ubTkcboyqdxffRKEEHqBDKnX77A@mail.gmail.com> <2DD56D786E600F45AC6BDE7DA4E8A8C1602BCB@eusaamb107.ericsson.se>
In-Reply-To: <2DD56D786E600F45AC6BDE7DA4E8A8C1602BCB@eusaamb107.ericsson.se>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/tzdist/BEF7fsmCl6ZYhsvyd4g1qBzPx4s>
Subject: Re: [Tzdist] AD review of draft-ietf-tzdist-service-07 - Sections 8 - 10
X-BeenThere: tzdist@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <tzdist.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tzdist>, <mailto:tzdist-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tzdist/>
List-Post: <mailto:tzdist@ietf.org>
List-Help: <mailto:tzdist-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tzdist>, <mailto:tzdist-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 May 2015 18:27:09 -0000

That is essentially my feeling.

  It's good to make implementors aware of these issues - there probably 
isn't sufficient awareness in general.

What we choose to do about it is another issue - but at least we've been 
told.


On 05/12/2015 02:11 PM, Daniel Migault wrote:
> Hi,
>
> I believe there is a consensus that there are privacy issues, and that they should be documented. Whether they will be followed or ignored is another thing. I find it better to ignore while understanding their implications.
>
> My interpretation is that some of the issues have been raised by the WG, but we got a significant among of comments from the saag review. My understanding is that the WG agreed on the raised issues. I believe it is good these issues are being raised in order to document potential issues and information leakage. How the recommendations should be followed depends on the level of privacy that clients or servers want to implement and may be balanced with additional aspects.
>
> BR
> Daniel
>
> -----Original Message-----
> From: Tzdist [mailto:tzdist-bounces@ietf.org] On Behalf Of Barry Leiba
> Sent: Tuesday, May 12, 2015 1:15 PM
> To: Cyrus Daboo
> Cc: tzdist@ietf.org; draft-ietf-tzdist-service@ietf.org
> Subject: Re: [Tzdist] AD review of draft-ietf-tzdist-service-07 - Sections 8 - 10
>
> Another batch we're almost set on.  I just want to ask one further question about the insanely over-paranoid privacy stuff (yes, you can infer my view on this, you can...).
>
>> There was a thorough security/privacy review by Daniel Kahn Gillmor
>> that lead to the current text in Section 9 (see tzdist mailing
>> messages with "[saag]" in the subject).
> ...
>> Anyway, I am not sure, beyond some small clarifications, if anything
>> needs to change in this section. Certainly it needs input from
>> SAAG/Security ADs if we do decide to make changes now. Perhaps this
>> should be left to an IETF wide review (with another call to SAAG folks to pay attention to it)?
> I don't have time right now to read the email thread (about to leave for vacation until Sunday, back to work on Monday), but I'd like to know one thing here: Does the tzdist working group have real consensus on all this?  Or did it merely agree to what's there in order to get acceptance from the saag folks?
>
> Barry
>
> _______________________________________________
> Tzdist mailing list
> Tzdist@ietf.org
> https://www.ietf.org/mailman/listinfo/tzdist
>
> _______________________________________________
> Tzdist mailing list
> Tzdist@ietf.org
> https://www.ietf.org/mailman/listinfo/tzdist