[Dcrup] Warren Kumari's No Objection on draft-ietf-dcrup-dkim-crypto-13: (with COMMENT)

Warren Kumari <warren@kumari.net> Mon, 18 June 2018 20:07 UTC

Return-Path: <warren@kumari.net>
X-Original-To: dcrup@ietf.org
Delivered-To: dcrup@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 4EE41130E22; Mon, 18 Jun 2018 13:07:36 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Warren Kumari <warren@kumari.net>
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-dcrup-dkim-crypto@ietf.org, dcrup-chairs@ietf.org, fenton@bluepopcorn.net, dcrup@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.81.2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <152935245631.3584.15250692552339490015.idtracker@ietfa.amsl.com>
Date: Mon, 18 Jun 2018 13:07:36 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/dcrup/gEDAzi1AnzCsYn4-QT1SYoDlUBA>
Subject: [Dcrup] Warren Kumari's No Objection on draft-ietf-dcrup-dkim-crypto-13: (with COMMENT)
X-BeenThere: dcrup@ietf.org
X-Mailman-Version: 2.1.26
List-Id: DKIM Crypto Update <dcrup.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dcrup>, <mailto:dcrup-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dcrup/>
List-Post: <mailto:dcrup@ietf.org>
List-Help: <mailto:dcrup-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dcrup>, <mailto:dcrup-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Jun 2018 20:07:37 -0000

Warren Kumari has entered the following ballot position for
draft-ietf-dcrup-dkim-crypto-13: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-dcrup-dkim-crypto/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Section 7.  Security Considerations
"Ed25519 is a widely used cryptographic technique, so the security of DKIM
signatures using new signing algorithms should be at least as good as those
using old algorithms."

Could this be reworded? This might just be a pet peeve, but as it is written,
it is, I believe, false[0].

This says that, because lots of people use something, it must be good / secure.
That's like saying that because lots of people drink instant coffee it must be
at least as good as real coffee.  Adding something like "and has received lots
of review from the cryptographic community", or "doesn't seem to have any
weaknesses", or something would help. Oh, the Change Log "11 to 12" entry wins!
W

[0]: I bought a box of commas on sale this weekend.