Friday, August 13, 2010

Re: [Geopriv] [geopriv] #38: Section 1

On the security issue Hannes raised, I'm OK with the current statement in
Section 3 and don't believe anything more is warranted:

"
Since there is no privacy protection for DHCP messages, an
eavesdropper who can monitor the link between the DHCP server and
requesting client can discover this LCI.
"

As I/others have stated, confidentiality of DHCP messages on a modern wired
networks is inherent in the design or at layer 2. The applicability for
DHCP to hand out device-level location information on mobile networks is
simply not feasible or practical, hence implementers understand the
limitations of this mechanism.

-Marc-

On 8/10/10 5:10 PM, "geopriv issue tracker" <trac@tools.ietf.org> wrote:

> #38: Section
> 1
------------------------------------------+---------------------------------
>
Reporter: bernard_aboba@Š | Owner: bernard_aboba@Š
>
Type: defect | Status: new
>
Priority: minor | Milestone:
> draft-ietf-geopriv-3825bis
Component: rfc3825bis |
> Version: 1.0
Severity: Waiting for Shepherd Writeup
> | Keywords:
>
------------------------------------------+---------------------------------

> Marc Linsner said:

"Further, RFC3825 includes:

" Wireless hosts can
> utilize this option to gain knowledge of the
location of the radio access
> point used during host configuration,
but would need some more exotic
> mechanisms, maybe GPS, or maybe a
future DHCP option, which includes a
> list of geo-locations like that
defined here, containing the locations of
> the radio access points
that are close to the client"

Since
> draft-ietf-geopriv-rfc3825bis is updating RFC3825, it takes strong
consensus
> to add/remove text from RFC3825. Since this text is missing
from

> draft-ietf-geopriv-rfc3825bis, one has to assume the wg agreed to taking
it

> out.

You might want to go back and figure out why this text was removed and

> suggest that it's put back in, or modified and put back in."

[BA] It appears
> that the text in question was removed in -02, as part of
the merger of
> Sections 1 and 1.2, covered by Ticket #20. The proposed
merger was discussed
> on the list in September 2009 (see

> http://www.ietf.org/mail-archive/web/geopriv/current/msg07895.html ).

In
> addition to the text that was removed, some text from

> draft-thomson-geopriv-3825bis was edited into Section 1:

The options
> defined in this document have limited applicability for
mobile hosts.
> Typically DHCP clients refresh their configuration in
response to changes
> in interface state or pending lease expirations.
As a result, when a
> mobile host changes location without subsequently
completing another DHCP
> exchange, location configuration information
initially obtained via DHCP
> could become outdated.

[BA] By replacing the text on wireless usage with a
> statement of
applicability relating to mobile uses, the overall impression
> that
Section 1 leaves is a focus on wired uses.

--
Ticket URL:
> <http://trac.tools.ietf.org/wg/geopriv/trac/ticket/38>
geopriv
> <http://tools.ietf.org/geopriv/>

____________________________________________
> ___
Geopriv mailing
> list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv

_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv