RFC 7258: Pervasive monitoring is an attack
Summary
RFC 7258 explicitly declares large-scale passive monitoring a form of attack that protocol design must take into account. Threat models have to include powerful global observers. Encryption by default changes privacy for the whole network.
Ideas
- Passive observers collect content and metadata of many users.
- Encryption should become the normal case wherever possible.
- Protocols should avoid unnecessary observable data.
Remarks
- RFC 7258 has the status “Best Current Practice”; current errata and successor documents should also be checked.
Recommendations
- Enable encryption by default rather than as an option.
- Minimise unencrypted metadata and long-lived identifiers.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.