Re: [Uta] Barry Leiba's Yes on draft-ietf-uta-xmpp-06: (with COMMENT)

Peter Saint-Andre - &yet <peter@andyet.net> Mon, 20 April 2015 22:27 UTC

Return-Path: <peter@andyet.net>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 833C21B334B for <uta@ietfa.amsl.com>; Mon, 20 Apr 2015 15:27:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level:
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8Cr8eqlXUNB9 for <uta@ietfa.amsl.com>; Mon, 20 Apr 2015 15:27:33 -0700 (PDT)
Received: from mail-ie0-f173.google.com (mail-ie0-f173.google.com [209.85.223.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 112A41B3348 for <uta@ietf.org>; Mon, 20 Apr 2015 15:27:31 -0700 (PDT)
Received: by iedfl3 with SMTP id fl3so854868ied.1 for <uta@ietf.org>; Mon, 20 Apr 2015 15:27:30 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :cc:subject:references:in-reply-to:content-type :content-transfer-encoding; bh=Ukr+zovYuGH8LGtqToZCfhNzJbIu8/i7uEPRJuCYHDM=; b=LXaVqotmflEa8fR+Ts6GBubYAD7WjY+X/4bh1JmaNmqs1/+hdAcex0qEH7OQAn7HNx 2KpRijVIPYnZt4mzAljfhaJEf8X9cMYMgIsYa7kEltqZGPGPQxOJN9Lw5Jn6SXTmZm42 RRp46amhqTZ3F9IQEdgoasJGwaCQFwcFLwOjZSgQFNQvABZKYfsb94MPgDr7N4uF19Lo LOJ37TEgPvFdqZV5/frOXBRfO1fIExnhTlAGJ+nuYF1DqqLtGqDtMfLr3+4bbyL8ZvyZ /+khRy7qNJSxsDjG/WkL1PIho5I2IgDvjsgDrDxGHZfJLynp4ZrpyI5b2ahAqpi1y4F3 GPVQ==
X-Gm-Message-State: ALoCoQnI4q+r3kLvxoamP2uLMtu6GHkbBJzN1HJsTbhY30lV+TDNTvx4TOnY4ritgOX+PcM9Em95
X-Received: by 10.107.3.17 with SMTP id 17mr24222600iod.60.1429568850501; Mon, 20 Apr 2015 15:27:30 -0700 (PDT)
Received: from aither.local (c-73-34-202-214.hsd1.co.comcast.net. [73.34.202.214]) by mx.google.com with ESMTPSA id n8sm12160659ioe.37.2015.04.20.15.27.29 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 20 Apr 2015 15:27:30 -0700 (PDT)
Message-ID: <55357D50.1070307@andyet.net>
Date: Mon, 20 Apr 2015 16:27:28 -0600
From: Peter Saint-Andre - &yet <peter@andyet.net>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:31.0) Gecko/20100101 Thunderbird/31.6.0
MIME-Version: 1.0
To: Barry Leiba <barryleiba@computer.org>, The IESG <iesg@ietf.org>
References: <20150420214313.17988.96083.idtracker@ietfa.amsl.com> <55357667.3070309@andyet.net>
In-Reply-To: <55357667.3070309@andyet.net>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/uta/B9BFzAi2b98ENz8fcuHNe1r4n34>
Cc: uta-chairs@ietf.org, draft-ietf-uta-xmpp.ad@ietf.org, uta@ietf.org, draft-ietf-uta-xmpp@ietf.org, draft-ietf-uta-xmpp.shepherd@ietf.org, leifj@sunet.se
Subject: Re: [Uta] Barry Leiba's Yes on draft-ietf-uta-xmpp-06: (with COMMENT)
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Apr 2015 22:27:34 -0000

On 4/20/15 3:57 PM, Peter Saint-Andre - &yet wrote:
>
> On 4/20/15 3:43 PM, Barry Leiba wrote:

<snip/>

>> -- Section 3.6 --
>>
>> I understand that, while most users won't understand it, there's value in
>> trying to communicate to an end user that she is using a secure
>> connection.
>>
>> I am very skeptical that there's the slightest bit of value in giving end
>> users information about the version of TLS used, the mechanism for
>> verification, the details of the certs (if any), or the details of the
>> cipher suite.  I'm certainly skeptical that making that available to end
>> users should rise to the level of "strongly encouraged".  I'm not going
>> to block anything with regard to this, but I see this as something you
>> might strongly encourage be available to an administrator, but not to an
>> end user (other than, perhaps, by enabling detailed logging through an
>> advanced setting, then inspecting the logs).
>
> At one point in the history of this document, we had separate bullet
> lists for administrators and end users. There was so much overlap that
> it was confusing. However, we might consider bringing that back.

BTW, we based the user-oriented recommendation somewhat on current 
practices in web browsers. For instance, Firefox has an indicator 
showing whether a connection is encrypted, but also has an advanced 
option that enables a user to view the certificate and also see the TLS 
version and cipher suite (e.g., my connection to datatracker.ietf.org 
uses TLS 1.2 with TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256). I suppose we 
can argue about how useful this information is to a "normal" user, but 
deliberately hobbling XMPP clients in comparison to (some) web browsers 
seems less than completely helpful.

Peter

-- 
Peter Saint-Andre
https://andyet.com/