Re: crypto delay (Notes from Non-meeting)

From: Adam Shostack ^lt;adam@zeroknowledge.com>
Date: Wed Apr 03 2002 - 14:07:54 EST

On Wed, Apr 03, 2002 at 02:04:28PM -0500, Richard Shockey wrote:
> A
>
> >Perhaps this is a mistake? I think that emergency calling is complex,
> >and I'm far more concerned about my non-emergency privacy.
>
> Until its you that has the heart attack.

No, even then, I'm more concerned about my privacy outside of the
emergency. Or are you suggesting that the risks of having my
insurance company know about my eating habits are sufficiently
worrisome that I should worry about the privacy risks of location
phones at all times, even when having the heart attack? ;)

> >I'm also interested in trying, and would like to throw out the
> >suggestion that we might specify a level of crypto which is secure,
> >and offer nothing on slower processors. That would make sense if we
> >worry about roll-back attacks, and the ongoing cost of having weak
> >crypto in the system.
>
> I'm more concerned that the needs of the emergency response system are not
> impeded in any form I'm having the heart attack thank you very much
> ..adding complexity to the task of getting a location object from Point A
> to Point B is a "bad thing" tm. KISS strikes me as a more interesting
> foundation for protocol design.

By "offer nothing" I meant offer no security or privacy for the
location information, not no location information, such that we don't
get bogged down in figuring out what authorization scheme meets the
privacy requirement, the routing requirement, and the speed
requirement.

Adam
Received on Wed Apr 3 14:11:17 2002

This archive was generated by hypermail 2.1.8 : Thu Jan 22 2004 - 12:32:23 EST