Re: [urn] Stephen Farrell's Abstain on draft-ietf-urnbis-rfc2141bis-urn-21: (with COMMENT)

Martin J. Dürst <duerst@it.aoyama.ac.jp> Thu, 02 March 2017 12:14 UTC

Return-Path: <duerst@it.aoyama.ac.jp>
X-Original-To: urn@ietfa.amsl.com
Delivered-To: urn@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 739C3129975; Thu, 2 Mar 2017 04:14:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=itaoyama.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G5fHFNsetnr6; Thu, 2 Mar 2017 04:14:39 -0800 (PST)
Received: from JPN01-TY1-obe.outbound.protection.outlook.com (mail-ty1jpn01on0093.outbound.protection.outlook.com [104.47.93.93]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 796B712996F; Thu, 2 Mar 2017 04:14:38 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=itaoyama.onmicrosoft.com; s=selector1-it-aoyama-ac-jp; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=Ql4AL/4asmPKbRIFmj6Ae8nQmB/6U3nsP2RaVOqaiqc=; b=HBBFRxR3LnU/i2GY5o+LqTmGLIRIZJLfYaBBKDB+HFOQxDKRDyyjljOx0geJ7TPWFgS3lF6ow4NoBrPWX3ak6irvdalzG5aFPhXV57Qujt26vnlMlRl+ZIUiLkfkDPYrIPRjrmffjUK9yF2zGodqt0QOjcJ0TeoePYiHc5xPE1M=
Authentication-Results: computer.org; dkim=none (message not signed) header.d=none;computer.org; dmarc=none action=none header.from=it.aoyama.ac.jp;
Received: from [192.168.1.2] (223.218.130.44) by OS2PR01MB0643.jpnprd01.prod.outlook.com (10.167.176.141) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.947.12; Thu, 2 Mar 2017 12:13:46 +0000
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, Peter Saint-Andre <stpeter@stpeter.im>, The IESG <iesg@ietf.org>
References: <148832863670.29552.9014381848292739838.idtracker@ietfa.amsl.com> <68d0ad57-9ba0-beb2-2fe4-2f036fce3e93@stpeter.im> <836b3132-def8-0534-487a-bc78b69ee82c@cs.tcd.ie>
From: "Martin J. Dürst" <duerst@it.aoyama.ac.jp>
Organization: Aoyama Gakuin University
Message-ID: <9b79dcf6-fdff-8c80-e644-efaa8651cb05@it.aoyama.ac.jp>
Date: Thu, 02 Mar 2017 21:13:44 +0900
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.7.1
MIME-Version: 1.0
In-Reply-To: <836b3132-def8-0534-487a-bc78b69ee82c@cs.tcd.ie>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Originating-IP: [223.218.130.44]
X-ClientProxiedBy: OS2PR01CA0123.jpnprd01.prod.outlook.com (10.174.152.17) To OS2PR01MB0643.jpnprd01.prod.outlook.com (10.167.176.141)
X-MS-Office365-Filtering-Correlation-Id: cfd41cc9-ff61-43b8-8a90-08d4616593a5
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001);SRVR:OS2PR01MB0643;
X-Microsoft-Exchange-Diagnostics: 1; OS2PR01MB0643; 3:M9SRj5+f5uQ8oQmE67yAZqE4sdysScRbvMaae+OQql5BNHW85SIugtf4z7Lozgpsr1uutzKCrUa3tRQBYGFN96pWV1y5km4KrT89uC7QwPdHkQXwop6G3wCSKsiohQDyJfEh3JxpmdrT+qnq28uSphB3ZfJflL6aHf5Q4F052o6BL3aueAZWtkmkpXXk9q9tPBo2bII9FhHzrVTP6VOGTRbq6H25aFGaFUso3qt86ew9+eAQvlL6cIENheKFNYs0rNJDgMH2q1DA9zr5sDnIcw==; 25:PJtGKg6n5ItsblGeDN3M62AJiRkaKoMgTYnKkHxUAXN5vQheh4ymrLLRMIhvV4zYE/GNRrwGSo+ejwehkSsH7f99FBLTCObnI+KdkE5C5OW1U9oVbliGB7psORrOKzpz+Q/YBVsfXdu6QTGcQXojAbJX7Nm054rHLL2HBeZAQQdop8QbPttFxF1hQKYN19xDdPANFAtucq/wmLtbijeaOxrh8DxeLRbwNFMuTLtxmiF5jsQ0Z7Fe7hFTBVtWjJi4XO5kdP74F1mLu8PqAjyv6OdNTr+aMWtnAjITYRyLKC1CsA4QFpOMvZt9qPG/LUFD881XJjXSCWVAmvbLtX5MZnj9LDFWdULIOYbDuq3rkpElUOcjZlZqJpgNkvG/7boCzuJQtJFRJNGRDNSUFj7u3X9EqG1jkYgFKzsCtAQBuiOBS5kfzzzXaX16cwVVZDEQZdFGRyrnoZIF5pVsMgtMOA==
X-Microsoft-Exchange-Diagnostics: 1; OS2PR01MB0643; 31:KiLP3IU0E0vszbtu/dc5u0a8KzZV69FdZWRcdMVZ23Gtt5tngWAhatYJv9pO0BCt2lWLEKlXNhvpdYlwpWZl6E5yNDMODYO+2LNx5zDktevUJ1rXfqHrYdDdARYyNqT/T+qWSX2s0wxuC+affv4fpqa3GKMhVGyH1GMmVsZzszbR+LnFHtkVKBRGfz2gzn/yf093tWK1KTFdAobzIDl+FnYqVXOUoUW9XZlVdq1eLfrUZorm3MM2ZbBxQUYNBiLnkfRw1Ft0vq4WoLZqyd6xxg==
X-Microsoft-Antispam-PRVS: <OS2PR01MB0643EB880A72C7FB00DC597ECA280@OS2PR01MB0643.jpnprd01.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(278428928389397)(120809045254105)(192374486261705);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040375)(2401047)(5005006)(8121501046)(10201501046)(3002001)(6041248)(20161123560025)(20161123555025)(20161123562025)(20161123564025)(20161123558025)(6072148); SRVR:OS2PR01MB0643; BCL:0; PCL:0; RULEID:; SRVR:OS2PR01MB0643;
X-Microsoft-Exchange-Diagnostics: 1; OS2PR01MB0643; 4:lBbG/gLMzyXwGz/NraOZu76IqdsBZyMzn84Md2QqfwbDRWtj148ubk7tg3Hi2H7dwB+nsiSwWQTGKa7LnkPWE5eUX7YmJHotXrhdKsB9h7vf6JdcmxBIu4qkSSdihhMOBeDJehPNssft7muSs7hVmv8pa136qQOQhG6Cs734DPBSvXYLH7LoL6RLTteCuYy42QtBPJHgEEYH0fKOzz5bfPaPcrSJXC2V7BqUY4TELFFkJzp0Pzv7vn8RRACCL06T4rpfOURcjugAsUKfrPVSKdWkWQXz70JM6+q+naqeZQTuF1GpZRRXGR38s/GCWxUvSfmbZvivztSoQfpMukaAQv/Zm/rXStFaYefhlbdrIcgbEXLyUEuyAQPjQm1VHiibPMKRBfhv0DUBixh6j1p9NyZckgqZMzUwP+JU7R47J5FbCpqPSVMkfmYl5P9DwE6KQ4QqJhf38W0bJ68+Mo400QGUAx/+5nJaDsdMgoGwsugXWCqaBskSRzmsgiFh4qzQ2C6iH0ntZ619DUH00Czwj4z1YmZXof7VS9kHgsL/EalzOl6UYsQPChHHxesj/9wCdrppByzkdvMGnYJRkp8uobQ41V5HeiPRKNq+6oVct+Eyy8+hJYO4tqXj3G5h9rywD5Gk9CrGocqw63+Iy6nLCZaTejb7vHn5XnW8kdKwGz1ym3P6sZkEj285sglUq7QYXZPGzrvhXU4kJk2wa4ACNw==
X-Forefront-PRVS: 023495660C
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(6049001)(6009001)(7916002)(39450400003)(24454002)(6306002)(229853002)(74482002)(2950100002)(6486002)(90366009)(77096006)(42882006)(33646002)(42186005)(4326008)(31686004)(53546006)(7736002)(305945005)(54906002)(92566002)(53936002)(230783001)(6246003)(230700001)(189998001)(117156001)(38730400002)(6116002)(3846002)(50466002)(66066001)(81166006)(25786008)(2906002)(5660300001)(83506001)(50986999)(76176999)(47776003)(8676002)(65806001)(86362001)(31696002)(23676002)(54356999); DIR:OUT; SFP:1102; SCL:1; SRVR:OS2PR01MB0643; H:[192.168.1.2]; FPR:; SPF:None; MLV:sfv; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;OS2PR01MB0643;23:Zg1Yrrhv6Zj5DFtByTelh67L2TnS0K1WSwXAlyjymTYikRosclnPEMEB0TBQeEeZRF0JK6EQ2QafnirH/Ale0utc58wowqQNcYs0/Srr5+xOVYPhkB+aPmbcsht+eheoel+20OFovIjJ3j65o3+c1p0KZ3kfc9i2pNo/yOUkKxPJGpTJp5HEKrD+KP90XrUp8rhHMw0nWUqo16Affb3rW3QLv5+lGXffWkN99CIjyM5zIhW2oxBCdzZIR1K9/Oc5KO/tcSP6Jv4YzAJRHWViVobedY7/UAeQbx2Y5KaSo7tBt8yZ6byTp7Xe+BbpN/+mT5tIvam+Mr4pbFwYof9VAqfXPvebtPv5bAa1bCBRdlsszKxHVn7WMmwmo5bt1UnDY/CjkTDuGVPh6r1H6MSzcMW16eYyJO/WiOzn4U74ol+J/2y4BaEJ1v5xgEgB/arN86ODSEBB1Xm7mqS1J88NWa8i/YOPgy+ABcB2SWHgjPdQaW4cXqSa7Hv5FFFHRf+QRNGye4EzmYcdr08YEn6V/CvJ76S5N8ZUZ7GOFc2RctzLyBMHdveZOxsrJhqY+nHPybxm8eY+biE4fT/ej7LyY3dSi8jSqb0kViFkQk9FS4DG5TSxPyaxV6v7wDD0CXPIVIbl/RBw2epFzgxNaEX9d+NXp4CAqt0pTvNqIxncFdWaRe5VFCCpmniNV24GxPSbKECzPtZQ2WFG8K2evDqz/2j1B+1t3hm9dj1HL9FzXIN4ZOgZ8i6gtwM65wnbIJZ4EB8G3/FufVQj5MYN1L4gcuj6YvSMrD6nhfgbC26t2ZQRlZMt9FeOTTAZbGZE1roUB+2hyX9viStcoiv9/XoEC6yNNV9qCbU/DspsbqePa+MltaDBlsl1yBxeVQqSkjdLctoszuE8ZL1LyvTqdP9aJ8/zhN2Iy9YrNA77AuPEKO81qqSODHqjbtUa8auKlUxlz8J8tt9nwCoGVWDLqLJZ8mQ4GAsi0ir47W2SefrCbji29JDu6bywtHY3ZJ8tTtHvoeN+N93Y+ztJA3OywbIdG3u6X+B8CU3R2UaN7iOvyxktmn19hmGSOVQQnGgCLLOvnfgECZEgrXIYWy9T8QLpnIhuEPNb4OnSuc+uBCxT1+ft8Q0uwanfi9+qJsnGZDwFnTEFGUCLJofXWKsxWUAunw==
X-Microsoft-Exchange-Diagnostics: 1; OS2PR01MB0643; 6:pJpbvq/regAruWFbnS0FJisKuWkdcBtt2vc3TSrV5OLfRsc18ccojWhnsZLlSvCZYwN5VMxoWRAICUO4ltSn/1K61bmvp+JY1c/sO7zYKdUjD51a15qE2vWNm8ERzwL5xnp/NK0YPdNFiVWZ2aZxaZUHXi4/YA0w509Da4AXJokAfHPePBamQBvcOrMLiJ6AT7qlaLRrRuOP+ceRaYzBiG2lR7MNc/gO4mNmLQGaiHHrOm5YQXXXJUUicm9muF7wdvuixdh2T18V7vuNNsyTsgvomgtjlXtttslXKHfQAcIJ4msJ2PPnpk8SWlRDW0EAULpHUlwwBPmiLh273gRMm3yvWY5sUbdph3bMwWI3mkHUikZlJmymfXSzNfsLEfKwvcLuKftWOFFnP/+9TusONA==; 5:WTb5JUB607NcgbFwcIThlkjZ639bOiN8IgpyoNI16E7ZQIxor8YlPgfL/+CCVIcGXjzPrVYGnEHLmwyeEQ6GHDnefCIYLJW1/Tvzasgtps53gUriwvtA3HME/O9Ahn4o2gXjwvtIShOntHQIw7eEfw==; 24:9HemI+Y/rvYIu+g+9hUwrJwns+/Gexl2S++RXbMmy22OEZY9Jrc7zeFQJHUi5T2pgLPxA9dPqVqHwIg01ID9yGm+/Vh5Uq7eQjKVMXbIWs4=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; OS2PR01MB0643; 7:5Te6yeggtcHqKJ9t7DzP0bqeIhpvIjG8YS9yIAHANWiJAmV9aqI07qk25RTNNoL/DbGgDeX4n/C4aePOt2PQgulfaNrqsRLSsoIh8OKwGft3sISiaYd1wQeflzUHxqFPWrNm2odrt8QSndIHGSy5pXH75BLJuMN1DSMQRPw/SkOxeiIXlOt2Pvxi05ZQtforayerD5delKolYgRh5baPg5y4nPIYfUhgZ+MCvi6xEviHz17i5yagrf7T/2oDx0d7F88VauKtAeMUQdk6dx9fPsN69mYrBtJe53b1vKMPPp3ArS6OLoc3KXFUJeG2DlR0D9k9cfjcqJMd3qyrPUBJ3g==
X-OriginatorOrg: it.aoyama.ac.jp
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 02 Mar 2017 12:13:46.1054 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: OS2PR01MB0643
Archived-At: <https://mailarchive.ietf.org/arch/msg/urn/JKsosBc03dOWg7XVoYZeO1VthnM>
Cc: urn@ietf.org, draft-ietf-urnbis-rfc2141bis-urn@ietf.org, urnbis-chairs@ietf.org, barryleiba@computer.org
Subject: Re: [urn] Stephen Farrell's Abstain on draft-ietf-urnbis-rfc2141bis-urn-21: (with COMMENT)
X-BeenThere: urn@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Revisions to URN RFCs <urn.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/urn>, <mailto:urn-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/urn/>
List-Post: <mailto:urn@ietf.org>
List-Help: <mailto:urn-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/urn>, <mailto:urn-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Mar 2017 12:14:41 -0000


On 2017/03/02 17:11, Stephen Farrell wrote:
>
> Hiya,
>
> On 02/03/17 03:14, Peter Saint-Andre wrote:

>> Perhaps you could clarify what some of your concerns are here, above and
>> beyond the use of URIs in general (after all, a URN is a URI). Reading
>> between the lines, I imagine you might be worried that URNs within a
>> particular URN namespace (e.g., for U.S. Social Security Numbers or the
>> like) - once suitably resolved into one or more URLs - might enable an
>> attacker to determine a person's physical location (e.g., via IP
>> address) or actual identity (e.g., a pseudonym could "resolve" to a real
>> name). Are these guesses on the mark?
>
> Yep. Perhaps things like including an IMSI or IMEI (or
> values easily correlated with such) in the NSS part is
> what it'd useful to call out. I'm not sure if there are
> real examples of such in existing URNs but if there were

https://datatracker.ietf.org/doc/rfc7254/history/

Regards,   Martin.

> it'd be a fine thing to note that including such things
> imposes (often unmet) requirements for e.g. confidentiality
> on protocols and applications that use those URNs. If
> may also be useful to say that things like hashing the
> privacy sensitive value before inclusion in the URN don't
> prevent correlation and can be as "good" for re-identification
> as the non-hashed value.