Re: End-to-End Encryption Milestone

Dave Cridland <[email protected]>
Newsgroups gmane.ietf.xmpp
Message-ID <CAKHUCzxK=2+RoSBzPHax8S1oqb2gA5CRC9OR7ggzHhxV+AUL_g@mail.gmail.com>
On Tue, Feb 25, 2014 at 12:11 PM, Tobias Markmann
<[email protected]>wrote:

> I think what's really needed is some kind of overview/comparison document
> about that current status. While the current requirements document is a
> start in listing some potential requirements, modern IM use cases are a bit
> more complex, w.r.t. multi-device and the mobile application scenarios.
>
> So basically a document that compares existing proposals, like OTR, PGP,
> XTLS and maybe even some more general e2e IM security solutions like the
> TextSecure protocol or multi-party OTR, and analyze those regarding their
> security, support for PubSub/MUC, support for offline messages, support for
> multi-device usage, and possibly even more.
>
>
That sounds really useful. I suspect that:

a) Even quite experienced XMPP developers probably don't know what's on
offer, and what they provide.

b) It'd help focus discussion enormously, by enumerating the requirements
properly.


> On Tue, Feb 25, 2014 at 12:23 PM, Dave Cridland <[email protected]> wrote:
>
>> Doing it within the XSF would *possibly* be simpler in terms of process.
>
>
> Indeed. I don't know if the IETF is the right place for a status quo
> comparison document or if it'd be more attractive within the XSF with less
> process. I for one would gladly review and try to contribute as much as
> possible to such document. Reviewing current proposals and exposing their
> advantages and shortcomings, especially regarding multi-resource and
> offline usage, would be a great way to start looking for possible solutions
> for XMPP.
>
>
A comparison document such as you're suggesting could probably be done as
either; the process overhead isn't important either way. I suspect that
longer term, it'd be nice to maintain it (unless we think we'll find the
Final and Ultimate Solution to Encryption (FUSE), in which case it'll be
only useful as a snapshot.

If we want a "living document", then the XSF affords us that relatively
easily, whereas if we did it as an I-D, I wouldn't press for publication as
an RFC at all. In that sense, it'll be lower process within the IETF.

Dave.

_______________________________________________
xmpp mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/xmpp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.