Thursday, September 17, 2009

Re: [Geopriv] [geopriv] #22: Resolution does not define Geographic Privacy policy ?

Hi James,

I don't think that what you're talking about gets us much further with respect to privacy policy.

There are two aspects we need to address here:

1. policy relating to access control (authorizing the requester)

2. what information the protocol conveys about privacy policy (the geopriv usage rules)

I think that to some extent, what you are saying contributes to answering the first question. This also requires that we rely on the LCP policy (or Marc's new label).

What I infer from the text: "resolution does not define Geographic Privacy policy" is that this is an attempt to say that the information is not intended to convey geopriv usage rules. Of course, this is just inference - I'm not a mind reader.

If we want to address the second point, maybe we need to establish what the _implied_ geopriv usage rules are associated with the location information. For instance, is the DHCP client permitted to retransmit the information? In this case, I think that any answer other than 'yes' would be silly, but it might help to explicitly make this point.

--Martin

p.s. Just to challenge this:

> Much of time, DHCP servers will push -
> unsolicited - Options 123 and/or 99 towards
> clients. Meaning there is no RFC 3118 preshared
> key exchange, or anything else to verify who is
> asking for the information; mostly because no one
> asked for anything, yet it was still sent.

3825 recommends against sending option 123 without first receiving a request for it. The same is said in 4776 about option 99. Do implementers ignore SHOULD-strength recommendations in RFCs so consistently?

------------------------------------------------------------------------------------------------
This message is for the designated recipient only and may
contain privileged, proprietary, or otherwise private information.
If you have received it in error, please notify the sender
immediately and delete the original. Any unauthorized use of
this email is prohibited.
------------------------------------------------------------------------------------------------
[mf2]
_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv