Skip to content

Avoid bare 'for the sake of security'#974

Merged
royfielding merged 1 commit intohttpwg:masterfrom
kaduk:security
Sep 10, 2021
Merged

Avoid bare 'for the sake of security'#974
royfielding merged 1 commit intohttpwg:masterfrom
kaduk:security

Conversation

@kaduk
Copy link
Contributor

@kaduk kaduk commented Sep 9, 2021

Inspired by some discussion on #914 : while just the word "security"
is indeed used in marketing literature for proxies, it's meaning to different
parties is so varied so as to not really convey much useful information. In the
IETF we try hard to be clear about what security provides we need and/or provide,
avoiding the vague catch-all term. However (as I am reminded out of band), the
audience of this document is not exactly security experts, and it is easy to go
overboard trying to be precise, at least in this instance.

[actual commit message body retained below]

The mere act of inserting a proxy into the chain does not, in and of
itself, do much of anything for the security of the system (and a badly
implemented proxy can make the security of the system much worse).
A proxy can, however, provide security services such as auditing
access, annotating content from untrustworthy sources, exfiltration
avoidance, etc. It is these services that are the security-related
motivation for using a proxy, so say that "security services", rather
than just "security", are being provided by the proxy.

The mere act of inserting a proxy into the chain does not, in and of
itself, do much of anything for the security of the system (and a badly
implemented proxy can make the security of the system much worse).
A proxy can, however, provide security services such as auditing
access, annotating content from untrustworthy sources, exfiltration
avoidance, etc.  It is these services that are the security-related
motivation for using a proxy, so say that "security services", rather
than just "security", are being provided by the proxy.
@royfielding royfielding merged commit f9375fc into httpwg:master Sep 10, 2021
reschke added a commit that referenced this pull request Sep 10, 2021
Copy link

@mosi2021v mosi2021v left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants