RE: Reposted Comments on SCMP ( by Graham Klyne )
bartley.o'[email protected] Fri, 28 May 1999 15:34:13 +0100
| Newsgroups | gmane.ietf.scmp |
|---|---|
| Message-ID | <[email protected]> |
As this protocol is designed for sending financial information I would have thought that privacy was of the utmost importance. I suggest that ALL the SCMP header fields should be encapsulated within an encrypted MIME body part with nothing more than the minimum MIME headers required for delivery appearing outside the message body. In particular, no message-id and no from. The first thing a receiving agent should do is decrypt the incoming message to access the SCMP control fields and verify the signature. The MIME from field, the SCMP-sender-name and the digital signature all contain an identity. That is 3 names, all potentially different, in one message which is from one sending agent. I suggest that, as the signature name is a legally enforceable identity, the other two, from and SCMP-sender-name, are redundant and should be removed. (The from is only really needed to provide a human readable identity for mail applications.) >2.2 SCMP Sender Name > >The SCMP-sender-name header is used to designate the SCMP sender name. >Thereby the sender name can be accessed before any decryption of the >request is performed. Server implementations MAY reject the request >based upon sender name, before any message processing occurs. Unless the SCMP Sender name is contained within a signed component it is very dangerous to base any processing on it. A denial of service attack could easily be mounted by simply corrupting the sender name, causing rejection of all messages or unwanted processing by changing it to another valid name. An easily readable name gives instant knowledge to an attacker of the existence of a relationship between the sender and receiver. Easily readable SCMP control fields further identifies the relationship as a financial one. Simply collecting this type of information and publishing a "Customer/Account holder List" could be very damaging to the public image of a financial organisation like a Bank. >7.7.2 Server Errors. If the SCMP control information includes a generation date and an expiry date it will only be necessary to store message id's, to protect against replay, for a restricted period of time. If we are receiving financial transactions there will be a requirement to store them for a minimum period both for non-repudiation purposes and regulatory requirements. I'm getting on my soap box... An Inland Revenue letter looks like an inland revenue letter, a pin mailer looks like a pin mailer and a court summons looks like a court summons, Our postmen/women could probably tell a lot about our private lives from looking at the post we receive. In an ideal world ALL post would be sent in 12" cube cardboard boxes and we would have privacy. In an ideal electronic world all messages would be sent signed THEN encrypted with minimal routing information only on the outside. In this way it would be impossible to determine any information about the message. Regards, Bartley. Bartley O'Malley Citibank NA Lewisham House 25 Molesworth Street London SE13 7EX England Tel +44-171-500-6473 Fax +44-171-500-8880