[saag] Re: [EXT] Interests on Initiating the standardiza tion work related to "Zero Trust"?

Muhammad Usama Sardar <[email protected]> Thu, 8 Jan 2026 14:17:59 +0100
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
On 08.01.26 13:22, Michael P1 wrote:

> While the scope of technical threats is broad and continued wide 
> ranging discussion is valuable, personally I think that the objectives 
> and goals of that list, your research proposal on confidential 
> computing, and the current drafts on Zero Trust are all fairly 
> distinct. I’d worry that grouping everything together would mean that 
> no-one gets what they are after.
>
Sure, if you think keeping them separate is better, that's perfectly 
fine. It was just a proposal to see if it makes sense.
>
> For what it’s worth, I agree with some of the views expressed earlier 
> in the thread on Zero Trust. Working on about the definition of ZT 
> isn’t something that is likely to lead to productive outcomes,
>
Indeed, as you see in the thread, I am also against defining the term 
Zero Trust.
>
> and some of the initial drafts proposed have significant security 
> problems, as outlined by Paul and Michael.
>
I see problems too. To me, that is an indication that some research work 
is required.
>
> We discussed at the Real World Cyber Security side meeting in 
> Montreal, and highlighted by Richard in this thread, there is has been 
> significant effort at IETF on identity/authentication/authorization 
> technologies, but it’s still an area that we see exploited in practice 
> - I’d be keen that we use the expertise at IETF to discuss how we can 
> help users/implements/enterprises to prevent some of these issues
>
To me, that is a research question, and in large parts, what I am also 
interested in -- hunting for exploitable areas and informing the 
implementers before these areas are exploited, providing guidance to 
them how to do it securely -- but in a narrowed scope of confidential 
computing and AI.

-Usama

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/pkcs7-signature, 4.7 KB) - not displayed