nanog mailing list archives
Re: Adding GPS location to IPv6 header
From: Jimmy Hess <mysidia () gmail com>
Date: Mon, 26 Nov 2012 19:33:02 -0600
On 11/26/12, Alex <dreamwaverfx () yahoo com> wrote:
This would be great for troubleshooting things...I agree, but other than that it would create a whole new plethora of privacy concerns.
Just about every new technology, IP itself included has privacy concerns,
related to it; which is really just a fancy new name for security
confidentiality
concerns, regarding WHO is doing what things on the network. That doesn't
mean you blacklist those technologies.... In fact, in some cases
_identification_ of network nodes is a very good thing.
I would like very much for spammers to be identifiable, even at the
cost of some so-called "privacy" (not that embedding IP location data
helps with that)....
Heck, HTTPS has privacy concerns, because it requires a certificate,
containing
personal details of the server to operate. I suppose it would be
rather interesting if the certificate contained GPS details as well,
if end hosts' IP stacks were required to verify the GPS data is
either accurate or not present, and SSL clients were expected to
validate that the details in the IP packets matched, and if a list of
GPS positions was declared as a critical X509 extension.
Then a third-party hosting provider would not be able to be used to
spoof a HTTPS site (without the intruder gaining root access, in
order to spoof IP packets).
The existence of privacy concerns, does not mean you hesitate to implement a
protocol in any way, shape or form.
Privacy concerns,mean you as a user of that technology, pull out your handy
dandy risk calculator, and weight the details carefully consider,
what the probability
and impact of the various risks actually are -- what bad things can actually
happen, if the detail X is exposed, and what (if any) mitigations you
choose for
your particular scenario.
Which will for end users typically involve setting a local policy such as:
o Don't turn on the "Populate Packet headers with Location data"
Or:
o Don't stamp packets with location data, except to trusted hosts,
when stamped packets are sent with headers encrypted over VPN in tunnel mode
Or:
o Introduce sufficient error, that the GPS data does not
significantly compromise location
--
-JH
Current thread:
- RE: Adding GPS location to IPv6 header, (continued)
- RE: Adding GPS location to IPv6 header Dave Edelman (Nov 25)
- RE: Adding GPS location to IPv6 header Ammar Salih (Nov 25)
- Re: Adding GPS location to IPv6 header William Herrin (Nov 25)
- Re: Adding GPS location to IPv6 header Eugen Leitl (Nov 25)
- Re: Adding GPS location to IPv6 header Jimmy Hess (Nov 25)
- Re: Adding GPS location to IPv6 header John Adams (Nov 25)
- RE: Adding GPS location to IPv6 header Network IPdog (Nov 25)
- RE: Adding GPS location to IPv6 header Randy (Nov 25)
- Re: Adding GPS location to IPv6 header Eugen Leitl (Nov 26)
- Re: Adding GPS location to IPv6 header William Herrin (Nov 25)
- Re: Adding GPS location to IPv6 header Alex (Nov 25)
- Re: Adding GPS location to IPv6 header Jimmy Hess (Nov 26)
- RE: Adding GPS location to IPv6 header Mohacsi Janos (Nov 26)
- Re: Adding GPS location to IPv6 header Carlos M. Martinez (Nov 26)
- Re: Adding GPS location to IPv6 header Eugen Leitl (Nov 26)
- Re: Adding GPS location to IPv6 header William Herrin (Nov 26)
- Re: Adding GPS location to IPv6 header Harald Koch (Nov 26)
- Re: Adding GPS location to IPv6 header Eugen Leitl (Nov 26)
- Re: Adding GPS location to IPv6 header William Herrin (Nov 26)
- Re: Adding GPS location to IPv6 header George Herbert (Nov 26)
- Re: Adding GPS location to IPv6 header Owen DeLong (Nov 26)
- Re: Adding GPS location to IPv6 header George Herbert (Nov 26)
