[saag] Re: on derivative work rights statements in emails to Security Area mailing lists
Nico Williams <[email protected]> Sat, 22 Nov 2025 11:32:44 -0600
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <aSHzvC8t4B1Z/xJc@ubby> |
On Sat, Nov 22, 2025 at 10:55:53AM +0100, Simon Josefsson wrote: > There is added complexity because WG's get to chose Informational vs > StandardsTrack, and there are sometimes interactions of that decision > with IANA policies on what is required to allocate a code point. That > interaction seems mostly unfortunate. Not in this case. The registries in question are not Protocol Action required but Specification Required. > I think we should have code points for non-hybrid PQ algorithms. Hard to argue against that given the the assignments have been made. I'm not in the habit of tilting at windmills. > I think we should have Informational/Experimental RFCs specifying > non-hybrid PQ in IETF protocols like TLS, SSH, etc. They should warn This there is still time to prevent, though it's very unlikely to happen. > users about the dangers of non-hybrid PQ algorithms. They should do that, yes, if published. We can likely achieve IETF consensus that they should when they come up for IETF LC, and probably WG concensus when they come up for WGLC. > I think we should NOT have any non-hybrid PQ on the Standards Track or > Mandatory-To-Implement/Deply now. I think we can likely achieve IETF consensus for that proposition. > Non-hybrid PQ is a clear and real security risk, and the mitigation > (hybrids) are relative low-cost. +1 > The Informational/Experimental RFCs on non-hybrid PQ would allow us to > gain confidence in those protocols, and they could later be upgraded if > people are comfortable. +1 Nico -- _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]