Re: Statuses and response codes (Was: RE: [Simple] Status summary)

Paul Kyzivat <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
While the privacy concerns are significant, it seems to me that they should be largely equivalent in the two mechanisms. Someone who is intent on learning as much as
possible about my status will use every feature at hand, so hiding information via one channel but not the other is not useful.

Presence is not useful if it gives information that is often inconsistent with what I would discover by sending a MESSAGE or INVITE.

If I want to lie about my presence, then I should also set my UA up so that it lies in a consistent way to callers.

	Paul

Christian Huitema wrote:
> 
> >       - Open: you can expect a 200 for the MESSAGE
> >       - Away: you probably can expect a 2xx
> >       - Closed: you can expect a 4xx, or a 202, but not a 200 for the
> 
> We have to be a bit careful with this line of reasoning, and consider
> the privacy implications. I would argue that the response to MESSAGE
> SHOULD NOT provide an indication on the recipient's online status, or at
> least not in the general case. Otherwise, MESSAGE can be used as a
> covert channel to assess someone's presence status without going through
> the authorization mechanism built in subscriptions. Indeed, it may be OK
> to provide such status when the source of the message is an authorized
> subscriber to the user's presence, but you should also be a bit careful
> that the source URI is not forged.
> 
> Before anyone shrugs off the privacy complaint, consider the spooks'
> practice of locating a suspect's cell-phone. In a few occasion, the
> location was directly followed by a well targeted missile... From that
> point of view, the SMS' "read acknowledge" feature is terrible, and we
> should make sure to not emulate it.
> 
> -- Christian Huitema



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.