Re: [Uta] Eric Rescorla's Discuss on draft-ietf-uta-smtp-require-tls-07: (with DISCUSS and COMMENT)

"Alexey Melnikov" <aamelnikov@fastmail.fm> Wed, 13 March 2019 20:59 UTC

Return-Path: <aamelnikov@fastmail.fm>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2FB991311C1; Wed, 13 Mar 2019 13:59:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fastmail.fm header.b=zwnhFQi/; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=noW7mzh1
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id c8uiITGBHiqR; Wed, 13 Mar 2019 13:59:11 -0700 (PDT)
Received: from out2-smtp.messagingengine.com (out2-smtp.messagingengine.com [66.111.4.26]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7933F1311C0; Wed, 13 Mar 2019 13:59:11 -0700 (PDT)
Received: from compute7.internal (compute7.nyi.internal [10.202.2.47]) by mailout.nyi.internal (Postfix) with ESMTP id 6C21421F49; Wed, 13 Mar 2019 16:59:10 -0400 (EDT)
Received: from imap1 ([10.202.2.51]) by compute7.internal (MEProxy); Wed, 13 Mar 2019 16:59:10 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fastmail.fm; h= message-id:in-reply-to:references:date:from:to:cc:subject :content-type; s=fm2; bh=Lx8/XDXAZDQ3DMmkYJ3eOaT0x+IbbcGvlJ8+shI a5ks=; b=zwnhFQi/ERbtVZ6gNIQy3FUa2XeOH3tUbRQ0GA2zu3i8zffg2lIYi8j QRbqfHa8/WPMih2z+EAnxevJDAeBqwkhQWT3eh5Ts3jUtfKx0F5wieg4uKRIax2R u64k1MdOB//iAIsTO18e/S3kvY7fi5gOFYeXKog8zLAzBFz6E9t0bwHHG7Wu+al9 FLy/jYl1eH3W3tmMR2SPZ+nidXZGyQyu+UksAVQw8aBC9BSbuTQuyIR9urasL8uz IqDLVaaxf3+32bpYYwoK3mcAZUSXHYz2fiXz2xvqvMBflJHGC+CydlpSUtUFyOMZ RjDdr9+72ARFb4Q2/EdAaYN5zPIgJGA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:references:subject:to:x-me-proxy:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; bh=Lx8/XDXAZDQ3DMmkY J3eOaT0x+IbbcGvlJ8+shIa5ks=; b=noW7mzh16wkKH4R8abXxN26Ff+bi5bylk aPxJrlmqr68U0vuuKrOXPRmH/AO4YZSm2pzhBnrAPlyFCpDgXd6y04s2k+1MTYdR ZEu+m7I/NZqRpp7lsQ3TsK9NtJojC/pzyyf2Lx422yEdkg590acla80jz1FyioNt h5yLpxOWtuRQ6JOMbaSSrEDnDTJ2OoPV3nD7KK+SQ7S//M7QsQjPVsYUvLcq0csZ dMU3yrjvLHiaveIqyDC8dYYmCiLHpdabMsw8pS9sRz+xbqZdDNXGUx1UyDOviwQS naa6bL88P6hvwSNXOOHxb8DomXkOD8lHetktEaKLwQDrZEgAoFR0g==
X-ME-Sender: <xms:HW-JXMQ-KKujsFgDtI_k_uLMb_polzA4au6SyQqK1vMKRuX8_-h6Fg>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedutddrhedtgddugeegucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepofgfkfgjfhffhffvufgtsehttdertderreejnecuhfhrohhmpedftehlvgig vgihucfovghlnhhikhhovhdfuceorggrmhgvlhhnihhkohhvsehfrghsthhmrghilhdrfh hmqeenucfrrghrrghmpehmrghilhhfrhhomheprggrmhgvlhhnihhkohhvsehfrghsthhm rghilhdrfhhmnecuvehluhhsthgvrhfuihiivgeptd
X-ME-Proxy: <xmx:HW-JXApNmEe-4jkcbCGSbtBFEZhvVw1_2CAlz0n1XQLlgT8prEZnjA> <xmx:HW-JXGxK2QzLRUk4WeFIk0EzQCyOHffNCVWhD-nJw7Oo4r0eiwlB9g> <xmx:HW-JXNLBxGIhWpo4M7HfvZADTTVk2uHRp4edivbYaYYTnyWGiFfYbw> <xmx:Hm-JXMKFZ7YiAJI_W_-GWHnPDgrSbcm8nyevKdmonoTlpuMeVPyFqA>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id AAAFDD4833; Wed, 13 Mar 2019 16:59:09 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.1.5-925-g644bf8c-fmstable-20190228v5
X-Me-Personality: 21611513
Message-Id: <b60988cd-ef8a-46db-8d70-795954109bd3@www.fastmail.com>
In-Reply-To: <155076162945.8595.2671476533659571699.idtracker@ietfa.amsl.com>
References: <155076162945.8595.2671476533659571699.idtracker@ietfa.amsl.com>
Date: Wed, 13 Mar 2019 16:58:54 -0400
From: Alexey Melnikov <aamelnikov@fastmail.fm>
To: Eric Rescorla <ekr@rtfm.com>, The IESG <iesg@ietf.org>
Cc: uta@ietf.org, uta-chairs@ietf.org, Valery Smyslov <valery@smyslov.net>, draft-ietf-uta-smtp-require-tls@ietf.org
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/GbL0uUW-eagCH9PD6eF4IcmFJXA>
Subject: Re: [Uta] Eric Rescorla's Discuss on draft-ietf-uta-smtp-require-tls-07: (with DISCUSS and COMMENT)
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Mar 2019 20:59:13 -0000

Hi Ekr,

On Thu, Feb 21, 2019, at 3:07 PM, Eric Rescorla wrote:

> ----------------------------------------------------------------------
> DISCUSS:
> ----------------------------------------------------------------------
> 
> I support Benjamin's DISCUSS.
> 
> To elaborate on one point a bit: it seems to me that it's harmful to
> security to allow the sender to unilaterally override the recipient's
> preferences that something be encrypted. To forestall one argument,
> yes, the sender knows the contents of the message, but the recipient
> knows their own circumstances, and they may be at particular risk

I don't agree with this part of your DISCUSS and with your argument that this is the same as HSTS (I will try to gather my counter-arguments in a separate email), but in the interest of being constructive: can you suggest a possible fix (or directions towards the fix) to address your DISCUSS?

Thank you,
Alexey