jordi.palet--- via Security-wg <security-wg@ripe.net> wrote: > My point has never been “we must use email only”, but “let’s make sure > that we all use the same protocol” and nobody needs to develop > something for each possible operator where abuse is taking place. I > think XARF can do it, other ways are feasible, but the point is to > ensure that if you get a report and ignore it, you’re accountable for > it. At the recent Vienna IETF meeting, I had a conversation about PCAPNG link types, and abuse reports, and the often need to pseudonymize packet traces. The immediate desire was to be able to have an encrypted (pcapng) block that provided the needed seeds/mappings to undo the pseudonomization once the report gets to a party that can actually act on the contents. Researchers who want data against which to test hypothesis, do training, or gather stats about trends don't need to decrypt. Still, there is a need to be sure that data can't be inferred by other means. There are many papers that point to how poor some shrouding attempts really are when combined with other sources. Being able to collect and comment on traces (not just L2/L3 ones, but also re-assembled, inside of TLS traces of abuse) would probably also help. I imagine a Jupyter-like work page that can be collaboratively amended, and maybe transformed into a playbook. -- Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works -= IPv6 IoT consulting =- *I*LIKE*TRAINS*