[saag] Re: Attacking standardization

Nico Williams <[email protected]> Sat, 22 Nov 2025 01:33:12 -0600
Newsgroups gmane.ietf.saag
Message-ID <aSFnOJq/+n5F6UcH@ubby>
On Sat, Nov 22, 2025 at 06:09:35AM -0000, D. J. Bernstein wrote:
> Within NSA's 2013 quarter-billion-dollar budget to "covertly influence
> and/or overtly leverage" systems to "make the systems in question
> exploitable", one of the budget items was to "influence policies,
> standards and specification for commercial public key technologies".
> See the word "standards" there? Or look at
> 
>     https://web.archive.org/web/20250827175413/https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
> 
> saying "hybrid solutions may be allowed or required due to protocol
> standards".

I think appealing the WG chair's decision won't go anywhere.

I think the remaining available approaches within the IETF are:

 - attempt to deny these I-Ds IETF consensus during IETF Last-Call

and/or

 - a) submit an Internet-Draft directing the RFC-Editor to not publish
   RFCs specifying non-hybrid PQ ciphersuites, then b) get it published
   as a BCP _before_ any such RFCs get published.  (b) means getting
   IETF and IESG consensus -- I can't forecast how that would go, but
   IMO it's worth a try.

If all that fails there's the possibility of creating bad PR for these
RFCs.

At the end of the day heading off this attack will require goodwill.
And it will require significant effort and PR -- the sort that headed
off Clipper.

Nico
-- 

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]