Re: Comments on draft-cooper-privacy-policy-01.txt

2010-07-11 Thread Randy Bush
That started when Jeff Schiller was security AD. Though I can't remember who actually did the code. Though at the time the issue was no so much the carelessness of the users as the fact that the IETF password protocols were broken. i am not confident of either of those statements randy

Re: Comments on draft-cooper-privacy-policy-01.txt

2010-07-11 Thread Dave CROCKER
Hannes, On 7/9/2010 4:32 AM, Hannes Tschofenig wrote: The Fair Information Practices are a set of principles most of us are quite likely to believe in, such as (copied from the Alissa's draft): Likely, yes. But do any of us know how to translate those principles into particular behaviors?

Re: Comments on draft-cooper-privacy-policy-01.txt

2010-07-11 Thread Donald Eastlake
The sniffed passwords were sometimes displayed in real time on a monitor facing the audience from the front of the room. This activity was never called research that I can recall. I think the majority reaction was that this was a fine thing to motivate improvements in security practice. Only one