[saag] Re: Fragmentation, crypto drafts, and a way forwa rd

Stephen Farrell <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Hi Roman,

On 22/10/2025 23:20, IETF Chair wrote:
> [Roman] There is an implicit COI accusation in the above narrative.
> If impropriety in leadership has occurred, please personally file an
> appeal or encourage the party you are hearing these accusations from
> to do so to allow the matter to be reviewed.  See Section 6.5 of
> RFC2026.  We need that for the health and integrity of the IETF
> standards process.

I don't think it's at all likely that there's something here that
could be successfully appealed, and nor do I think Watson seemed
to be trying to allocate blame. IOW, I didn't interpret Watsons's
use of 'bias' to mean deliberate actions that might constitute a
CoI violation. (I'm sure he'll correct me if I got that wrong.)

I also do think it would be accurate to say that in the PQ space
the IETF currently does favour what NIST favours, so that might
provide some backing for Watson's concern. (Unless it turns out
I'm the one who told him stuff offlist, but while I don't think
I was, I have chatted with him about related topics so maybe it
was me... or not:-)

I think this all likely results from a bunch of factors (history,
locality for lots of active participants, business reasons for
sponsors etc.) that are fairly understandable, but it doesn't make
for a desirable situation even if there is no CoI anywhere. And
I don't actually think there is a personal IESG/AD CoI on this
topic myself. (I do think it undesirable to have an ex-NSA SEC-AD
but I've said that to Deb herself and also that I think she is
doing a very good job and hasn't shown any sign of problematic
behaviour that I've seen, but has instead gone out of her way to
try help sort out some of problems in this space ["hi ntru:-)"].)

As to what we should do about it - I think I'd suggest a different
approach to what Watson suggested: try have a saag discussion to
see if there's rough consensus that we're not doing this PQ stuff
very excellently and that we maybe should sit back and think some
more, without factoring NIST's views as heavily as we seem to have
been doing. That'd be very difficult for a bunch of people who are
invested in aspects of the PQ stuff currently being done, so it
is probably unlikely to happen, but I think we'd be happy in some
years' time if we took that approach and came up with something
better than the PQ-zoo for which we seem to have bought a ticket
(with NIST being the zookeeper).

Cheers,
S.

PS: I don't have anything against NIST (well, maybe Dual-EC:-),
but we seem to have moved from a position where we occasionally
have to do a little to handle some FIPS-140 quirk, to jumping
through hoop upon hoop of NIST-hoops when it comes to PQ things.
The latter situation seems less desirable to me, especially when
NIST-hoops, Brainpool-hoops and hoops-to-come all have inherent
conflicts. (Maybe my metaphor just broke down there:-)

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQQwbnhHy1kPJkWsM6fk2On5l6gz3QUCaPlpvQUDAAAAAAAKCRDk2On5l6gz3ZBf
APsFFv+/pv6W5G5yI9jhlJNcRvP3DxBChAActRmOkFkxQAEAg4oMukMfxD2sGI6D31p51qEYdUlB
i7HrzPBf2fQCwQA=
=ewoW
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.