Re: [p2pi] Charter and problem statement
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [p2pi] Charter and problem statement




On Jul 22, 2008, at 10:54 AM, Reinaldo Penno wrote:

This thread made the think that we need more security wording on the
charter.

I see ALTO maybe requiring a security document considerations of its own
besides the security section on each document.

There is clearly an expectation of privacy from the P2P client. There is clearly an expectation from the ISP that he is not aiding (conscientiously)
illegal file sharing, amongst others.

Actually, the expectation of privacy from a P2P client might be considered illusionary.

The whole point of P2P is you need to be able to discover peers, so any attacker who is authorized to participate in the P2P network (eg, able to get a Content-identifier from the tracker and therefore authorization to participate in the swarm) should be able to map at least part of the P2P network and, with sybils, generate a complete map.

Thus, for access to an ALTO server, the requirement should be "get NO more information than you could obtain otherwise as a participant in the P2P network", which is a huge amount, but generally safe. ("If you know the content/network/swarm ID, you can get the peer list, because you need to be authorized already to know this identifier").


The interesting question, however, is can an ALTO node, which ISN'T necessarily authorized to participate in a swarm, gain information on a swarm based on both queries to it, and also use any transactional information it gains to contact other ALTO servers to gain information about the swarm.

EG, it gets a content identifier based on a request, and then queries other ALTO servers to find out who else is participating in this content identifier.


In the end, it may be necessary to write requirements on information leaking that specifically fall one-way or the other, eg, "There is NO expectation of privacy because of X, Y, Z", or "Because of the client's expectation of privacy, when such is enabled, ALTO can't do A, B, C".


_______________________________________________
p2pi mailing list
p2pi at ietf.org
https://www.ietf.org/mailman/listinfo/p2pi



Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.