Service location vs. careless privacy infringement

Hallvard B Furuseth <[email protected]> Thu, 2 Jul 1998 15:00:06 +0200
Newsgroups gmane.ietf.lsd
Message-ID <[email protected]>
Has anything been done to prevent service location from magnifying the
problem of servers that carelessly ignore privacy protection?  This
needs to be addressed, but seems woefully absent from the documents I've
plowed through so far.

There are a lot of LDAP/directory servers that ignore privacy protection
laws.  As with WWW a few years ago, "everybody" are setting up such
servers, and a lot of them seem to forget about privacy protection.
Unindexed, such servers are in practice more or less local, so the
problem ism't that severe.  However, automatic service location will
magnify this problem enormously, at least location via the simple
convention DNS CNAME = <service>.<domain>.  We should not do that.

It may even be illegal to run a search robot in Norway which doesn't do
a reasonable job of exluding illegal servers.  Along with NameFLOW,
UNINETT wants to run a search robot which indexes legal LDAP servers.
(Well, servers that *claim* to be legal, I suppose.  We are not police.)
OTOH, we don't want to be outcompeted by a more careless robot abroad
which indexes all servers and is immune to Norwegian law.

BTW, if any of you are nearby, please give be a swift kick for not
mentioning this a few years ago:-(

--
Hallvard B Furuseth
UNINETT Directory Service