RE: RE: [Geopriv] Consensus on changes to location-conveyance

"Brian Rosen" <[email protected]>
Newsgroups gmane.ietf.sip,gmane.ietf.geopriv
Message-ID <[email protected]>
I don't really understand why you think location by reference is so much of
a concern.  If you look at the discussion in context, PIDF-LO defines
location as part of presence.  All of these concerns are relevant there, and
I think they have been adequately covered there.  We even have some work on
anonymization of the identity (and thus of the URI) in presence.  Generally,
a presence uri:

Is not valid for a limited amount of time
Is not hard to guess, if it uses an AoR and could be with anonymous URI.
Identifies the user if it uses an AoR and doesn't with anonymous URI

The protocol (SIP) for retrieving presence, and thus location has the
location ruleset as we defined for PIDF-LO, but otherwise does not have "no
cache" semantics (albeit caching headers is not very interesting in SIP).

Generally, presence systems do have user control of who is allowed to access
information, including location and identifying information, so I think that
is covered fairly well.

Proxy insertion of location, whether by value or by reference has the threat
of not being as subject to user control, but I think in every case you have
to trust your provider to do as you wish, whether it is your presence
provider or your location provider independent of your presence provider,
and proxy insertion doesn't fundamentally alter that.  I worry more about
it, but I don't objectively think it's much different.

Now, if there are other location dereferencing systems, they may need an
analysis like what you are suggesting, but with respect to SIP Presence, as
a form of location by reference, I think we have been over the ground
sufficiently, and we have RFCs that permit it.  Adding restrictions on the
Location header, which I propose is useful precisely to allow an anonymous
presence uri that does not reveal identity is not so great I think.  If you
don't allow that, you would kind of have to use an AoR, which may be
appropriate in some cases, but would not in others.

I think the proponents of proxy insertion argue that providing it means
endpoints don't have to do anything, so I would think they would object to
explicit permission to do so.  You might get away with a flag that says
"don't do it" in the IETF process, but whether such a flag would be deployed
is another matter.   I think we all agree that the emergency case is
different here; laws govern behavior, and in most cases compel location
assertion.

I kind of like the idea that the proxy inserts the header in the response so
the UAC can see it.  What do others think of that? 

Brian


> -----Original Message-----
> From: Jeroen van Bemmel [mailto:[email protected]]
> Sent: Tuesday, July 25, 2006 7:22 PM
> To: Brian Rosen; 'Marc Linsner'; Peterson, Jon; 'Andrew Newton'; Rosen,
> Brian
> Cc: [email protected]; [email protected]
> Subject: Re: [Sip] RE: [Geopriv] Consensus on changes to location-
> conveyance
> 
> Brian,
> 
> > Would you not agree that if a proxy is allowed to insert
> > location-by-value,
> > the concerns would be the same?
> 
> That would depend whether the URL dereferences the current location, or
> the
> location at a particular moment in time. The value of a URI with up2date
> location info is much higher and much more privacy invading than a one-
> time
> snapshot of a user's location. So perhaps same concerns, but much stronger
> 
> For location-by-reference, you'd probably want some additional
> requirements:
> - URL must be valid for a limited amount of time
> - URL must be cryptographically hard to guess
> - URL must not contain any information that identifies the user / device /
> AoR
> - for whatever transport protocol is used: response must be marked as 'no
> cache'
> - user must be able to remove the information at the URL, ie explicit
> invalidation
> - user must be able to verify correctness of the issued information (ie
> user
> can access the URL himself)
> - user must be able to control who accesses the URL, both upfront and
> history of accesses (for a reasonable period)
> - there must be explicit consent before a proxy would insert user location
> 
> For the latter point: except for emergency scenario's, the UAC should
> include some flag in the INVITE saying "proxy: please append location".
> You'd probably also want some feedback (eg proxy or UAS adding a header to
> the response saying 'this is the URL that I appended/got'
> 
> Regards,
> 
> Jeroen
> 



_______________________________________________
Sip mailing list  https://www1.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use [email protected] for questions on current sip
Use [email protected] for new developments on the application of sip
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.