Hello Roger et al.,

> Isn't the payload the important part to protect? the content of the package?

that's not enough. If reports in the press are correct then just the 
metadata alone, i.e. who is talking to whom, is valuable input for the 
various agencies.

True, for a court to judge you, harder evidence is necessary (or so I 
think but maybe it's just the hope of me powerless citizen :-)

So you would need to encrypt the whole original packet that is wrapped 
into Lisp. And even then I doubt you can avoid Metadata to "leak": Lisp 
is separating Identity from Location but this doesn't mean the RLOC can 
not be used to identify you. In case of static setups this is obvious, 
take the RLOC, go to the ISP, get the (physical) address and name. For 
mobile Lisp you could correlate your RLOC changes with the changes on 
the lower layers, i.e. when changing from one antenna to the next. 
Gives you the mobile's identification number and finally your identity.


You said in another email:

> One easy fix then would be to have a MUST encrypt traffic between
> xTRs, and that the encryption used MUST be strong. Are LISP@WG up for
> the challenge? :-)

I wouldn't be happy about the MUST (the first one ;-) to become part of 
Lisp specifications - Lisp turns out to be a versatile tool, encryption 
does not always fit the use cases and would turn into a deployment 
roadblock.
Different story is if Lisp and it's Database can support the 
integration of encryption - that sounds reasonable to me.


My $0.02

Regards, Marc




On Sat, 7 Sep 2013 15:05:48 +0200, Roger Jørgensen wrote:
> ---------- Forwarded message ----------
> From: Roger Jørgensen <[email protected]>
> Date: Sat, Sep 7, 2013 at 3:05 PM
> Subject: Re: decentralization of Internet (was Re: Bruce Schneier's
> Proposal to dedicate November meeting to saving the Internet from the
> NSA
> To: Noel Chiappa <[email protected]>
> Cc: IETF Discussion <[email protected]>
> 
> 
> On Sat, Sep 7, 2013 at 2:20 PM, Noel Chiappa 
> <[email protected]> wrote:
>>> From: =?ISO-8859-1?Q?Roger_J=F8rgensen?= <[email protected]>
>> 
>>> The userbase and deployment are relative small atm so it's doable to
>>> get fast deployment to.
>> 
>> Alas, now that I think about the practicalities.... I don't think 
>> the average
>> router has enough spare computing power to completely encrypt all 
>> the traffic.
> 
> I don't really see that as an issue, it's just a matter of engineering
> and building
> the router in a way that they can do it. AFAIK I think most routers have the
> options of being extended by dedicated encrypt-all-traffic tasks? 
> Probably some
> changes needed on the software layer to use the extension but that's doable.
> 
> It is also just the situation right now on the router side. In general
> should our
> current technology and processing power be up for the job if needed.
> 
> 
>> Whether or not encrypting just the source+dest addresses, and the sort+dest
>> port (conviently next to each other in one block) is enough to do 
>> much good,
>> and if the average router has enough spare crunch to do even that, 
>> is a good
>> question.
> 
> Isn't the payload the important part to protect? the content of the package?
> 
> 
_______________________________________________
lisp mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/lisp

Reply via email to