[saag] Re: Proposal for Discussion: The Secure Internet – Embedding Trust into the Protocol Layer

Eric Rescorla <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CABcZeBMnrr9CZL_Vk4MUP2kDL-woqHeCO0Z5yu_YTRgHCyH7vQ@mail.gmail.com>
Well, I don't see a copy of the email in the dispatch archives. Perhaps it
got filtered. In any case, this will need to go to secdispatch, not
dispatch.

With that said, I don't see the problem with producing an Internet-Draft.
It's a standardized format for presenting ideas. When I try to evaluate the
maturity/readiness of an effort I look at whether it has drafts and at how
much mailing list traffic it has. So, really, you should publish one. In
terms of the content, I think use cases are good, but some sort of sketch
of the architecture/design is also important.

-Ekr



On Mon, Aug 18, 2025 at 11:44 AM Thi Nguyen-Huu <[email protected]> wrote:

> Thanks, Eric.
>
>
>
> In my email to dispatch@[email protected] I included 8 pages describing the
> use cases. Maybe it would describe what the I-D would do even if not in I-D
> format? Would it help that I forward that email to this group?
>
>
>
> Cheers
>
>
>
> *Thi Nguyen-Huu | *CEO
>
>
>
> Tel: +1 905.502.7000 x 3288  |  Toll Free: 888.879.5879
> [email protected] |  www.winmagic.com
>
>
>
> *WinMagic Corp.* | 11-80 Galaxy Blvd.
>
> Toronto, ON  |  M9W 4Y8 |  Canada | www.winmagic.com
>
> <http://www.facebook.com/WinMagicInc>   <https://twitter.com/winmagic>
> <http://www.linkedin.com/company/winmagic>
> <https://www.winmagic.com/blog/>
>
> [image: A person holding a phone and typing on a computer AI-generated
> content may be incorrect.] <https://winmagic.com/en/secure_internet/>
>
>
>
> *From:* Eric Rescorla <[email protected]>
> *Sent:* Monday, August 18, 2025 12:29 PM
> *To:* Thi Nguyen-Huu <[email protected]>
> *Cc:* [email protected]; StJohns, Michael <[email protected]>; Salz,
> Rich <[email protected]>; Paul Wouters <[email protected]>; Sergei
> Nikitin <[email protected]>
> *Subject:* Re: [saag] Re: Proposal for Discussion: The Secure Internet –
> Embedding Trust into the Protocol Layer
>
>
>
> You don't often get email from [email protected]. Learn why this is important
> <https://aka.ms/LearnAboutSenderIdentification>
>
> CAUTION:This email originated from outside of the organization. Do not
> click links, open attachments or respond unless you recognize the sender
> and know that the content is safe.
>
>
>
>
>
>
>
> On Mon, Aug 18, 2025 at 7:07 AM Thi Nguyen-Huu <[email protected]>
> wrote:
>
> Dear SAAG members,
>
> I’m writing to follow up on my earlier outreach regarding *The Secure
> Internet* architecture. After further reflection and community feedback,
> I believe this initiative is best introduced through a *BOF (Birds of a
> Feather)* session rather than a standalone Internet-Draft.
>
>
>
> Typically the Internet-Draft is the basis on which the community
> determines (1) whether a BOF is warranted and (2) whether the WG should be
> chartered.
>
>
>
> At the end of the day, the IETF publishes specifications as RFCs, and so
> the I-D serves as some indication of what specification will eventually be
> published.
>
>
>
>
>
>
>
> The *Secure Internet (SI)* enables what legacy architectures deemed
> infeasible — and what users have long dreamed of:
>
>    - *No user action*: No passwords, no MFA, no friction.
>    - *Protocol-native protection*: Cryptographic defense against session
>    hijacking and adversary-in-the-middle (AitM) attacks.
>
>
>
> SI proposes a new trust model for the Internet — one that replaces static
> credentials and certificate-based authentication with *policy-bound
> cryptographic keys anchored in hardware*, available only when *organizational
> trust conditions* are met. This enables *non-interactive, mutual
> authentication* via mTLS without certificates, transforming how endpoints
> and services establish trust.
>
> Given the architectural scope — spanning transport security, endpoint
> identity, and trust enforcement — SI does not fit neatly into existing
> working groups. It introduces foundational concepts such as:
>
>    - *Live Key*: A dynamic identity signal tied to verified user presence
>    and device integrity.
>    - *LIM/TIM (The Identity Machine)*: A system that governs Live Key
>    availability based on policy.
>    - *MagicEndpoint*: A trusted channel between endpoint and IdP,
>    enabling continuous identity signaling.
>
> I believe a BOF is the right venue to:
>
>    - Explore the feasibility of a new working group
>    - Discuss technical foundations and deployment models
>    - Align with existing standards (TLS, FIDO2, RATS)
>    - Define a roadmap for multiple RFCs under the Secure Internet umbrella
>
>
>
> This may or may not be true, but nevertheless, an I-D is the right place
> to lay out this argument.
>
>
>
> -Ekr
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
image001.png (image/png, 1.4 KB) - not displayed
image002.png (image/png, 1.3 KB) - not displayed
image003.png (image/png, 1.4 KB) - not displayed
image004.png (image/png, 1.4 KB) - not displayed
image005.png (image/png, 222.4 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.