[saag] Re: on derivative work rights statements in emails to Security Area mailing lists
Christian Huitema <[email protected]> Fri, 21 Nov 2025 13:49:37 -0800
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
On 11/21/2025 10:07 AM, Nico Williams wrote: > Speaking of which, I've not followed all your appeals, but regarding the > non-hybrid PQ ciphersuites, I'm afraid that ship sailed the moment the > IANA registry was made Specification Required. I.e., in that particular > case neither the WG chair, nor the AD, nor the IESG can provide relief. > I share your concerns about that case FYI! IMO we should absolutely not > allow non-hybrid PQ for at least a few years out of an abundance of > caution, but, again, I think it's too late and we can't really bring the > horse back to the barn. I think this boils down to an argument about power and authority of the IETF. Should the working groups act as gatekeeper and use their authority to "absolutely not allow" deployment of algorithms that they find inappropriate for the Internet? That would mean, of course, instructing IANA that only algorithms approved by Working Groups should be allocated code point. The problem with that is whether the IETF has enough moral authority to make such decisions stick. Sometimes it does -- see for example the rejection of various proposals to weaken encryption in TLS. If a substantial consistency wants to deploy something and the only thing standing in their way is a code point allocation experience shows that they will just squat on some random value, thus leading to a worst of both worlds. The IETF did not stop the deployment, and the squatted code point ends up having to be reserved to avoid collisions with existing deployments. That's why I personally think that the IETF should concentrate on making sure that safe algorithms can be easily deployed, rather than attempting to use the IANA as a gatekeeper. In the particular dispute between hybrid and non-hybrid, that means publishing and endorsing a good hybrid solution. By the way, the debate is not just about hybrid versus non hybrid. There is also a debate about how much deference the IETF should have to NIST. If we end up only recommending the technologies that NIST approved, then NIST becomes a single point of failure. Maybe we are OK with that because there are no credible alternative. Or maybe not. -- Christian Huitema _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]