Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

The IETF needed a wake-up call on security, says chairman

The Snowden revelations have made the standards organization rethink its approach on security

Article comments

Security and how to protect users from pervasive monitoring will dominate the proceedings when members of Internet Engineering Task Force meet in London starting Sunday.

For an organization that develops the standards we all depend on for the Internet to work, the continued revelations made by NSA whistleblower Edward Snowden have had wide-ranging repercussions.

"It wasn't a surprise that some activities like this are going on. I think that the scale and some of the tactics surprised the community a little bit. ... You could also argue that maybe we needed the wake-up call," said IETF Chairman Jari Arkko.

The security implications of the disclosures are something the IETF must deal with, according to Arkko.

"Obviously it's important that we have reliable tools for e-commerce, banking, private communications and everything else. My vision of the end goal is that we try to build a more secure Internet based on the assumption that there are all these threats around us," Arkko said.

Part of that work will also be to make security features easier to use and for the standards organization to think of security from day one when developing new protocols.

"It isn't easy to make these improvements, because if Internet security was easy we would have solved it years ago. But there are things that we can do and what I find very positive is that we seem to be going through this systematic analysis of the different parts to see what we can do with instant messaging, with the Web, with voice over IP," Arkko said.

In conjunction with the IETF meeting, the IAB (Internet Architecture Board) and the W3C (World Wide Web Consortium) are organizing a high-level workshop that will delve deeper into some of these challenges, including tradeoffs between strengthening security measures and performance.

Many topics will be discussed in London, including the "Internet of things" and what changes are needed to make the Internet a better fit for devices such as sensors that in many cases need to be energy efficient. Part of that work is a new protocol called CoAP (Constrained Application Protocol), designed to easily work with HTTP for integration while meeting requirements such as multicast support and low overhead.

But thermostats, wearables and sensors also need protection, including encrypted communications.

"At this meeting, we are talking about something that would enable authorization to work better in this environment. Even if you have security, you need to decide who can use the thermostat at home," Arkko said.

Digital currency is another area that the IETF has taken an interest in. The work is still at an early stage, so in London participants will consider whether there is a role the standards organization can play, according to Arkko.

"Are there parts of the communication that we could help with? Is there a need for further standardization?" Arkko said.

The IETF meeting is Sunday through Friday.

Send news tips and comments to mikael_ricknas@idg.com



Share:

More from Techworld

More relevant IT news

Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *