[saag] Re: Post-Quantum Resistance Cryptography Consideratio ns (was post quantum guidance draft)
Kyle Rose <[email protected]> Mon, 15 Dec 2025 09:02:45 -0500
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CAJU8_nWwTNYW-vc6e3BpXN=LwTZ7FxjQvKRVtmPRxTZDV0QmFw@mail.gmail.com> |
On Mon, Dec 15, 2025 at 4:57 AM Denis <[email protected]> wrote: > After more than 80 email exchanges on the saag list under the topic "post quantum guidance draft" , I have a proposal > and for this proposal, I changed the topic of the thread into: Post-Quantum Resistance Cryptography Considerations. > > All RFCs are required by RFC 2223 to contain a Security Considerations section. > RFC 3552, i.e., BCP: 72, issued in July 2003, has the following title "Guidelines for Writing RFC Text on Security Considerations". > > At the moment, all RFCs are not required to have a Privacy Considerations section. RFC 6973 (Privacy Considerations for Internet Protocols) states: > > "Whether any individual document warrants a specific privacy considerations section will depend on the document's content". > > In the same way: > > "Whether any individual document warrants a specific Post-Quantum Resistance Cryptography Considerations section will depend on the document's content. This practice of requiring sections with specific titles to elevate some design considerations above others and to encourage authors and reviewers to do the things they should already be doing may have negative consequences as those interested in security often jump straight to the section titled "Security Considerations" and assume it covers everything, which invariably it does not except in the most trivial cases, those with the infuriating "This document does not describe a protocol and has no security considerations." A document describing a complex protocol should already have a clearly demarcated section analyzing its security, and if it does not, then the authors, reviewers, WG chairs, and/or ADs are not doing their jobs. In this case, only a tiny percentage of RFCs will need to explicitly address PQ cryptography, adding to the already voluminous boilerplate noise in documents. We should end this practice, not add to it. Kyle _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]