[saag] Fragmentation, crypto drafts, and a way forward

Watson Ladd <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CACsn0ckdh7OU3hL6nyJyrJGcwS48djVXZf=YkqR-XQgsiUorHA@mail.gmail.com>
Dear SAAG,

Over the past few months there's been quite a bit of debate over the
appropriateness of having algorithm describing drafts emanate from
working groups particularly post quantum crypto.  That's despite many
groups opening up IANA registries to try to avoid these issues. I
suggest that we leave this up to working groups and let them decide
what they want to describe and with what track. We don't currently
have a clear signal to do otherwise in the form of IETF or security
area wide consensus, there is no reason to think there will be one,
and the current situation is a mess that working groups are best
positioned to navigate.

To be absolutely clear: I have been told privately, as well as seen in
public emails, that there is a bias towards NIST favored cryptography
on the part of IESG members and Security ADs who have intervened to
delay or downgrade publication of drafts that describe alternatives to
ML-KEM, and that this favors organizations they currently or in the
recent past have worked for. I don't think that there are widely used
protocols where ML-KEM hybrids or pure would not be an option, nor do
I think that diversity would become a major problem: that's why we
increasingly opened up the registries in TLS, and I think the market
would deal with this. I do think what's happening now is harmful to
the general environment of the IETF and creates a great deal of
unclarity.

Sincerely,
Watson

-- 
Astra mortemque praestare gradatim

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.