[openpgp] Re: Fwd: I-D list for Open Specification for Pre tty Good Privacy notification: Changes to draft-gallagher-openp gp-code-point-exhaustion

Justus Winter <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hi Heiko :)

Heiko Schäfer <[email protected]> writes:

> Hello Justus, list,
>
> On 3/20/25 10:57 AM, Justus Winter wrote:
>> Further, the proposed solution (for which reserving one bit now is the
>> precondition, so I think it is fair to also consider it), seems to
>> complicate parsing (and there is precedence on how OpenPGP very cleverly
>> encodes things like packet body lengths, S2K hash counts, S2K mechanism
>> type, AEAD block sizes), and I like parsing to become simpler, not more
>> complicated.
>
> I tried to be clear, but will try to be even clearer:
>
> I didn't mean to say that I'm in favor of ratifying the specifics of
> the proposal.  I *am*, however, in favor of *just* reserving code
> points >= 128 (where applicable), until further notice.

Thanks for clarifying.

> Reserving a range of code points, by itself, certainly wouldn't
> complicate any parsing.  It would only clarify a policy for how the WG
> assigns code points, over the next few cycles of extensions.

That is true.

> Reserving the upper halves *for now* wouldn't in any way stop the WG
> from deciding (say, 5 years from now) that it is, after all, the
> lesser evil to just assign code points >=128 in one-byte
> representation.

That is true, but this precaution also has a non-trivial cost (Andrews
time, our time, IETF machinery time), for a problem that not everyone
agree exists (in fact, a relatively recent discussion in this working
group concluded that it doesn't), and the precaution is necessary only
to pave the way for a solution no one except Andrew seems to like (at
least no one spoke up yet, if you do, please speak up!).

> (Fwiw, I currently lean towards agreeing with you - I expect to favor
> avoiding the complexity of Andrew's proposal, myself. But maybe in 5
> years my view will have changed.  I expect we will collectively gain
> new insights about the appropriate future evolution of the format, as
> OpenPGP hopefully flourishes.)

Thanks for carefully clarifying your opinion on the proposed solution as
well.


Best,
Justus

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 584 B)
-----BEGIN PGP SIGNATURE-----

wsC7BAEBCgBvBYJn3AhQCRCI3H4zOF95HUcUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcmez6OuC8HGkc+67s2CTwZoj0UXLR7IU7OeQG8s8tbQS
ChYhBCVqTlXkpy2XrSRo54jcfjM4X3kdAAAr4wgAi5jnYoRA2Cf/bgRHYcDlvdch
Y3dOADGwk8Mvm9cVI68WcFd2YmmjUiYC+p3ycPjqTQvKhyHN5jSUBfKWtpTkxY0c
5AnQbU6b9/DB6zMNGtXXybL0+/5k7jl9+31Wd+lK/ARuhsKg9DZ6T4zd/2PvUeWy
YZbNlhQ198/tYxF9QuKgQyBSWdL7lLovEL4Dext556hbMeiJTdTr4MJ0xTcEmh94
uPju7gi76kK3sPlL1hFD1DwBPkI67mP40286Efc4QjE7hCgg5Q8+NRdsmejPz9q0
5fdiepnG4Ztw3CEyxRfGtdane2OLGU///HpqcSDSl+3HfcOXMZWbtVyaAjIbtw==
=e0xo
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.