RE: Reposted Comments on SCMP ( by Graham Klyne )

bartley.o'[email protected] Fri, 28 May 1999 15:34:13 +0100
Newsgroups gmane.ietf.scmp
Message-ID <[email protected]>
As this protocol is designed for sending financial information I would have 
thought that privacy was of the utmost importance.

I suggest that ALL the SCMP header fields should be encapsulated within an 
encrypted MIME body part with nothing more than
the minimum MIME headers required for delivery appearing outside the message 
body. In particular, no message-id and no from.

The first thing a receiving agent should do is decrypt the incoming message to 
access the SCMP control fields and verify the signature.

The MIME from field, the SCMP-sender-name and the digital signature all contain 
an identity. That is 3 names, all potentially different,
in one message which is from one sending agent. I suggest that, as the 
signature name is a legally enforceable identity, the other 
two, from and SCMP-sender-name, are redundant and should be removed. (The from 
is only really needed to provide a human readable
identity for mail applications.) 

  >2.2 SCMP Sender Name
  >
  >The SCMP-sender-name header is used to designate the SCMP sender name.
  >Thereby the sender name can be accessed before any decryption of the
  >request is performed. Server implementations MAY reject the request
  >based upon sender name, before any message processing occurs.
Unless the SCMP Sender name is contained within a signed component it is very 
dangerous to base any processing on it. A denial of 
service attack could easily be mounted by simply corrupting the sender name, 
causing rejection of all messages or unwanted processing
by changing it to another valid name. 

An easily readable name gives instant knowledge to an attacker of the existence 
of a relationship between the sender and receiver. Easily
readable SCMP control fields further identifies the relationship as a financial 
one. Simply collecting this type of information and publishing
a "Customer/Account holder List" could be very damaging to the public image of 
a financial organisation like a Bank.


>7.7.2 Server Errors.

If the SCMP control information includes a generation date and an expiry date 
it will only be necessary to store message id's, to protect
against replay, for a restricted period of time.

If we are receiving financial transactions there will be a requirement to store 
them for a minimum period both for non-repudiation purposes and regulatory 
requirements.


I'm getting on my soap box...

An Inland Revenue letter looks like an inland revenue letter, a pin mailer 
looks like a pin mailer and a court summons looks like a court summons, Our 
postmen/women could probably tell a lot about our private lives from looking at 
the post we receive. In an ideal world ALL post would be sent in 12" cube 
cardboard boxes and we would have privacy. In an ideal electronic world all 
messages would be sent signed THEN encrypted with minimal routing information 
only on the outside. In this way it would be impossible to determine any 
information about the message.


Regards,
Bartley.

Bartley O'Malley
Citibank NA
Lewisham House
25 Molesworth Street
London
SE13 7EX
England

Tel +44-171-500-6473
Fax +44-171-500-8880