[saag] Re: [EXT] Interests on Initiating the standardiza tion work related to "Zero Trust"?

Michael P1 <[email protected]> Thu, 8 Jan 2026 12:22:29 +0000
Newsgroups gmane.ietf.saag
Message-ID <CWXP123MB3992B76106854F038881F40F8F85A@CWXP123MB3992.GBRP123.PROD.OUTLOOK.COM>
Hi Usama,

Firstly, thank you for looping me into this discussion.

As you mention, the recently set up practical-cybersecurity list is intended to be a venue for discussion and knowledge sharing on current cyber security threats and mitigations against them so as to upskill as a community, making the most of the range of different expertise that IETFers bring.

While the scope of technical threats is broad and continued wide ranging discussion is valuable, personally I think that the objectives and goals of that list, your research proposal on confidential computing, and the current drafts on Zero Trust are all fairly distinct. I'd worry that grouping everything together would mean that no-one gets what they are after.

For what it's worth, I agree with some of the views expressed earlier in the thread on Zero Trust. Working on about the definition of ZT isn't something that is likely to lead to productive outcomes, and some of the initial drafts proposed have significant security problems, as outlined by Paul and Michael.
We discussed at the Real World Cyber Security side meeting in Montreal, and highlighted by Richard in this thread, there is has been significant effort at IETF on identity/authentication/authorization technologies, but it's still an area that we see exploited in practice - I'd be keen that we use the expertise at IETF to discuss how we can help users/implements/enterprises to prevent some of these issues but I don't think the initial drafts here on ZT are the way to go.

Thanks,
Michael

From: Muhammad Usama Sardar <[email protected]>
Sent: 08 January 2026 09:08
To: Benfeng Chen <[email protected]>
Cc: Aijun Wang <[email protected]>; Salz, Rich <[email protected]>; Blumenthal, Uri - 0553 - MITLL <[email protected]>; [email protected]; Erik Johnson <[email protected]>; [email protected]; [email protected]; Hillary Baron <[email protected]>; Aijun Wang <[email protected]>
Subject: [saag] Re: [EXT] Interests on Initiating the standardization work related to "Zero Trust"?


Hi Benfeng, Aijun and others involved in this effort,

I have an offer for you:

  *   I am proposing a research group (not working group) to tackle the research questions around confidential computing [0]. After the side meeting, I met IRTF chair in Montreal and explained the idea. He seemed interested in the idea. We need to provide charter for further discussion. I plan to initiate this work in early Feb.
  *   Michael P wants to do some practical cybersecurity and he is quite open to ideas [1].

It seems to me what you want to do has some overlaps. Would it make sense to join all forces and define a scope for a research group which covers all of that? Once the research group is formed and some foundational work is done in that research group, we can propose one/more very specific working groups. Thoughts?

Also a couple of notes inline:


On 08.01.26 06:45, Benfeng Chen wrote:
I'm not comparing Noise with TLS here, as that isn't the focus of the discussion.
Nor was I. I was just expressing my doubts on the accuracy and recency of information there.


Both WhatsApp and NHP initially chose the Noise protocol because it was considered secure and fast for their respective threat models. Meta's later transition to attested TLS was driven by deployment and integration requirements for confidential computing, not by any identified weakness in Noise itself.

Well, not being quantum safe is itself a weakness of Noise, while TLS WG offers quantum-safe solutions. Google folks (Tiziano Santoro and his colleagues) told me at Linux Plumbers Conference in Tokyo that they will most likely not be pursuing efforts on attested Noise for this reason.

-Usama


[0] https://mailarchive.ietf.org/arch/msg/124attendees/Z7fg3_OAW4lJtgrU68oZLFdCLxw/

[1] https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/1jZfkhUQem9ru7oSvR5noWujQ44/

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]