RE: RE: [Geopriv] Consensus on changes to location-conveyance
"Brian Rosen" <[email protected]>
| Newsgroups | gmane.ietf.sip,gmane.ietf.geopriv |
|---|---|
| Message-ID | <[email protected]> |
I don't really understand why you think location by reference is so much of a concern. If you look at the discussion in context, PIDF-LO defines location as part of presence. All of these concerns are relevant there, and I think they have been adequately covered there. We even have some work on anonymization of the identity (and thus of the URI) in presence. Generally, a presence uri: Is not valid for a limited amount of time Is not hard to guess, if it uses an AoR and could be with anonymous URI. Identifies the user if it uses an AoR and doesn't with anonymous URI The protocol (SIP) for retrieving presence, and thus location has the location ruleset as we defined for PIDF-LO, but otherwise does not have "no cache" semantics (albeit caching headers is not very interesting in SIP). Generally, presence systems do have user control of who is allowed to access information, including location and identifying information, so I think that is covered fairly well. Proxy insertion of location, whether by value or by reference has the threat of not being as subject to user control, but I think in every case you have to trust your provider to do as you wish, whether it is your presence provider or your location provider independent of your presence provider, and proxy insertion doesn't fundamentally alter that. I worry more about it, but I don't objectively think it's much different. Now, if there are other location dereferencing systems, they may need an analysis like what you are suggesting, but with respect to SIP Presence, as a form of location by reference, I think we have been over the ground sufficiently, and we have RFCs that permit it. Adding restrictions on the Location header, which I propose is useful precisely to allow an anonymous presence uri that does not reveal identity is not so great I think. If you don't allow that, you would kind of have to use an AoR, which may be appropriate in some cases, but would not in others. I think the proponents of proxy insertion argue that providing it means endpoints don't have to do anything, so I would think they would object to explicit permission to do so. You might get away with a flag that says "don't do it" in the IETF process, but whether such a flag would be deployed is another matter. I think we all agree that the emergency case is different here; laws govern behavior, and in most cases compel location assertion. I kind of like the idea that the proxy inserts the header in the response so the UAC can see it. What do others think of that? Brian > -----Original Message----- > From: Jeroen van Bemmel [mailto:[email protected]] > Sent: Tuesday, July 25, 2006 7:22 PM > To: Brian Rosen; 'Marc Linsner'; Peterson, Jon; 'Andrew Newton'; Rosen, > Brian > Cc: [email protected]; [email protected] > Subject: Re: [Sip] RE: [Geopriv] Consensus on changes to location- > conveyance > > Brian, > > > Would you not agree that if a proxy is allowed to insert > > location-by-value, > > the concerns would be the same? > > That would depend whether the URL dereferences the current location, or > the > location at a particular moment in time. The value of a URI with up2date > location info is much higher and much more privacy invading than a one- > time > snapshot of a user's location. So perhaps same concerns, but much stronger > > For location-by-reference, you'd probably want some additional > requirements: > - URL must be valid for a limited amount of time > - URL must be cryptographically hard to guess > - URL must not contain any information that identifies the user / device / > AoR > - for whatever transport protocol is used: response must be marked as 'no > cache' > - user must be able to remove the information at the URL, ie explicit > invalidation > - user must be able to verify correctness of the issued information (ie > user > can access the URL himself) > - user must be able to control who accesses the URL, both upfront and > history of accesses (for a reasonable period) > - there must be explicit consent before a proxy would insert user location > > For the latter point: except for emergency scenario's, the UAC should > include some flag in the INVITE saying "proxy: please append location". > You'd probably also want some feedback (eg proxy or UAS adding a header to > the response saying 'this is the URL that I appended/got' > > Regards, > > Jeroen > _______________________________________________ Sip mailing list https://www1.ietf.org/mailman/listinfo/sip This list is for NEW development of the core SIP Protocol Use [email protected] for questions on current sip Use [email protected] for new developments on the application of sip