Then we read 2804 differently.     When I read 2804,  the contained discourses 
on what is and is not wiretapping,  clearly says to me,  that what Enterprises 
do within their networks,  is NOT wiretapping according to 2804 (or to me for 
that matter).  

We (and many others in this discussion),  have different perspectives.   
Perhaps this is a contributing reason the Chairs determined it should continue. 
    I sincerely hope this will lead to some mutually acceptable dialogue and 
related solutions.  



-----Original Message-----
From: Stephen Farrell [mailto:[email protected]] 
Sent: Monday, July 10, 2017 3:37 PM
To: Ackermann, Michael <[email protected]>; Polk, Tim (Fed) 
<[email protected]>; [email protected]
Subject: Re: [TLS] chairs - please shutdown wiretapping discussion...



On 10/07/17 16:30, Ackermann, Michael wrote:
> Given the above scenario,  I do not understand how this can be construed as 
> "Wiretapping".    2804 seems to make this clear.

TLS is much more widely used that you seem to imagine.

Please see the comments to the effect that there is no way to control to 
location of the wiretap/TLS-decrypter in the protocol.

If that's not obvious, I don't know how to explain it further.

See also text in 2804 wrt tools being used for more than initially envisaged.

And if coercion of a server to comply with a wiretap scheme like this stills 
fanciful to you, please check out the history of lavabit - had there been a 
standard wiretap API as envisaged here it's pretty certain that would have been 
the device of choice in a case like that.
While it's easy enough to envisage many other abuses that could be based on 
this wiretap scheme, that one is a good match and a real one.

> Such critical colloquy,  with significant long term impact,  should 
> not be prematurely terminated,  IMHO

"Premature" is nonsense, this debate has gone on too long already.

S.




The information contained in this communication is highly confidential and is 
intended solely for the use of the individual(s) to whom this communication is 
directed. If you are not the intended recipient, you are hereby notified that 
any viewing, copying, disclosure or distribution of this information is 
prohibited. Please notify the sender, by electronic mail or telephone, of any 
unintended receipt and delete the original message without making any copies.
 
 Blue Cross Blue Shield of Michigan and Blue Care Network of Michigan are 
nonprofit corporations and independent licensees of the Blue Cross and Blue 
Shield Association.
_______________________________________________
TLS mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/tls

Reply via email to