Re: [125attendees] [Gendispatch] Re: Re: Re: Re: Re: Re: Last IETF ever in China ?! Re: Agenda request: draft-rescorla-anonymous-network

"Mirja Kuehlewind (IETF)" <[email protected]>
Newsgroups gmane.ietf.general
Message-ID <[email protected]>
RFC8718 already has this requirement:

"This includes, but is not limited to, access to corporate networks via encrypted VPNs from the meeting Facility and Hotels, including Overflow Hotels.”

Asking chairs to disable the VPN to address an imminent network problem wasn’t appropriate but this request was also quickly revised to, if possible, use an egress close to Singapore.

Sorry to diverge a bit from the original discussion topic, but the actual solution to address this problem with VPN and chairing is to provide an extra computer at the chairs desk to be used during chairing. We used to have that but that it was somehow at sometime replaced by a machine used by meetecho that the chair are not supposed to touch.

Mirja



> On 23. Mar 2026, at 21:23, Chris Inacio <[email protected]> wrote:
> 
>> On 20-Mar-26 10:54, Tommy Jensen wrote:
>>> (no hats on)
>>> 
>>> I don't get how this distinction matters unless we assume "IETF
>>> attendees do not have the right to expect the onsite network is free
>>> from expected and contract-dictated attacks" is a true statement. I
>>> don't, and the opposite ought to be written down.
>>> 
>>> Note: none of this needs to be political. This would apply to very local
>>> venue decisions to do the same (i.e. the sovereign nation has a free and
>>> open Internet access, but the venue hotel requires active monitoring of
>>> all attendees for some reason). Whether the venue requires it because of
>>> national law, local law, the whims of the general manager, or the
>>> configuration of the network infra vendor is irrelevant to the harm to
>>> attendees.
>> 
>> +n
>> 
>> The only thing we should consider is whether a meeting can be conducted
>> effectively without unacceptable privacy harm to participants. _Why_ the
>> harm happens is irrelevant. Defining "unacceptable" is the hard part.
>> 
>>  Brian
>>> 
>>> Thanks,
>>> Tommy
> 
> (Also no hats on for me)
> 
> So under this approach, I propose the following assumptions and question:
> 
> (1) Many participants are corporately sponsored
> (2) Corporate systems often are required to run corporate security suites on their machines including VPNs
> (3) Employees are often forbidden from disabling those VPNs
> 
> Should the IETF have a policy that enables those participants to attend and not violate their corporate policies?
> 
> If the IETF should enable / allow that, how should it be done?
> 
> Should the IETF have folks walk around and tell people to drop the VPN because it interferes with our conferencing experience?
> Should the IETF have people attempt (if possible) to reconfigure the end-point of their VPN to accommodate the meeting-to-meeting configuration of the services?
> Should participants pay more so that the IETF can great expand its on site and cloud presence to resolve the conflict from a restricted on site network vs. remote participant connection to resolve the issue with “brute force”?
> 
> 
> 
> _______________________________________________
> 125attendees mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.