Pervasive Monitoring Is an Attack (2014)
tools.ietf.org
tools.ietf.org
If pervasive monitoring in nsa style is legal and culturally accepted, then the solution must be cultural, not technical. Either by embracing the death of privacy and having no real secrets, or by convincing hearts and minds of the immorality of the monitoring until it is outlawed and people who do it are jailed.
Also, the BCP does not contend that an technology end-run around law exist (or that it is desirable). The BCP is about mitigating, not entirely preventing, the threats described: "'Mitigation' is a technical term that does not imply an ability to completely prevent or thwart an attack. Protocols that mitigate PM will not prevent the attack but can significantly change the threat."
Surely, given commercial practices such as HTTP header injection by Verizon and the Pharma saga in the U.K., a BCP that promotes privacy/security thinking in the design of new protocols is a good thing. Which is not to say that attackers, commercial or otherwise, will not find other ways; but let's at least try to increase the bar by weeding out unnecessary attack surface and information leakage.
This doesn't mean we should just facilitate pervasive monitoring.
Hard to comment on it in a general sense. There's lots of forms of pervasive monitoring.
Seems somewhat specific.
Also relatively specific, without being overly so.