From nobody Mon Apr 26 14:15:27 2021
Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id ABEEF3A304B
 for <ietf@ietfa.amsl.com>; Mon, 26 Apr 2021 14:15:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level: 
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
 NICE_REPLY_A=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001,
 URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
 header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id XzdnyH2XGGSu for <ietf@ietfa.amsl.com>;
 Mon, 26 Apr 2021 14:15:21 -0700 (PDT)
Received: from mail-pj1-x1036.google.com (mail-pj1-x1036.google.com
 [IPv6:2607:f8b0:4864:20::1036])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 7D2FC3A304A
 for <ietf@ietf.org>; Mon, 26 Apr 2021 14:15:21 -0700 (PDT)
Received: by mail-pj1-x1036.google.com with SMTP id
 y22-20020a17090a8b16b0290150ae1a6d2bso6071232pjn.0
 for <ietf@ietf.org>; Mon, 26 Apr 2021 14:15:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; 
 h=subject:to:cc:references:from:message-id:date:user-agent
 :mime-version:in-reply-to:content-language:content-transfer-encoding;
 bh=HDY0k9wwyxj5Aemx5x8mhtjppPh6T1bVHjZBi68htFQ=;
 b=qy4V4ppuIuLMxkYe0/FQx/ScSrh0zE6/UoEQnJ1mkDbprjuc8ajyTAzWWgZKDtLGBO
 8Oly9MaJWRebddIpnaVTx+AosQbNjJNJlvaw6zr0pw7sxPIh7vF8OIFd4usR8GwO19KT
 voN1dN02Gvn0rPPJv4Sa4Pluz86J5RUcWbchi4bw4ocjpF9DY5DoaaNeRX+ESP25WD2M
 JXpMhLpZ/T0mDEnLxidZ0SNNzguCuQrckcYv095vmuRcJd65PitcqJkNxHy29aSz/iZM
 bTJtJWfBGzDTn7FtwKQl34mLNQ97Ek4UfBFRjFj18PrlJljvS8mtXrfY6fKnU+2+NwOS
 QB2w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20161025;
 h=x-gm-message-state:subject:to:cc:references:from:message-id:date
 :user-agent:mime-version:in-reply-to:content-language
 :content-transfer-encoding;
 bh=HDY0k9wwyxj5Aemx5x8mhtjppPh6T1bVHjZBi68htFQ=;
 b=jbrkXz6Xg4xLv3mxcOll5VmM23de/qd3YZ/McEyurttmczt/RndGd4nN20IWgVqEIF
 Frmo58n9j7bwrXdMyf49hP6GtfqXZU4MmRNOmDFU6SeSJcvy7WPWWzK2TiNi0NK24NMV
 841L72WiUcqerIDwPDWUocCJ3niILSW+UodDbqUi2fP+hixPUdCl0tvzEC1xoO2w/MTb
 /OoizcdHKrlYlMldUmKjpDkRhTb86d39DfGi5+7aLPNvt2OzKJLc4Pvhfz0xBQGaDcRH
 FKtHoPzOqYvm972HTiYUsNXRQU9rzpRfVvxaov0BXeNSCV6n3MOHrkJ8tPSplAJ+ckrL
 xdkw==
X-Gm-Message-State: AOAM533uN7f1iedWLSo00nw3yNXVCtm8FJPb5ySKNhLZnZAZSvgXq52D
 kre4+UDx7viqi6aBacnCgZSR7K4qrsyaxQ==
X-Google-Smtp-Source: ABdhPJwcJ1ddyUrFtdu0FZP3bwWyx4rn8PTAmVMVmsltOnffKzq1QQmdRZnpbKbAAwXvvlkZIB/bng==
X-Received: by 2002:a17:90b:4017:: with SMTP id
 ie23mr1123419pjb.155.1619471718963; 
 Mon, 26 Apr 2021 14:15:18 -0700 (PDT)
Received: from [192.168.178.20] ([151.210.131.14])
 by smtp.gmail.com with ESMTPSA id d4sm264935pjz.49.2021.04.26.14.15.16
 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
 Mon, 26 Apr 2021 14:15:18 -0700 (PDT)
Subject: Re: Escalation: time commitment to fix *production* security bugs for
 BLS RFC v4?
To: Quan Thoi Minh Nguyen <msuntmquan@gmail.com>
Cc: "Salz, Rich" <rsalz@akamai.com>, "ietf@ietf.org" <ietf@ietf.org>
References: <CAAEB6g=tU=MF1_QKduEN55ft0rWe+7x0wBbywS083fJrjzP=XA@mail.gmail.com>
 <CAAEB6gn+QWuCX4BxCJuofz6JF6amaPtWiDtg7ZAmRT9FwaX8vA@mail.gmail.com>
 <C2025926-ECD9-4846-BE36-9B243000DF5F@akamai.com>
 <CAAEB6gm710=5KrNEpVPWRKpMWFupcYFuCBiHP80=BwOormiABg@mail.gmail.com>
 <30B2523F-F116-454A-BE64-349A260F54D7@akamai.com>
 <CAAEB6gm2815anAJyugVkah5dFBQxEawHiGtodk2q=O4g8Q+kOA@mail.gmail.com>
 <DA7E8D75-2643-431A-A043-0C0317F5A824@akamai.com>
 <CAAEB6gnXi20_15DoJx9AEQ2V3J-T5ViPRjSKCtJhOHBKHUZEBA@mail.gmail.com>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Message-ID: <f1e71e0a-7ab7-3716-28ed-c9a37aafda6f@gmail.com>
Date: Tue, 27 Apr 2021 09:15:13 +1200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101
 Thunderbird/60.9.1
MIME-Version: 1.0
In-Reply-To: <CAAEB6gnXi20_15DoJx9AEQ2V3J-T5ViPRjSKCtJhOHBKHUZEBA@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/A8MaBwNpbWf_DJoWj0sRROIml3Y>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>,
 <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>,
 <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Apr 2021 21:15:26 -0000

Hi Quan,

I think you are misunderstanding something here. Yes, of course, bugs and=
 weaknesses in draft documents need to be fixed. Actually that is a very =
large part of what happens in all IETF mailing lists and meetings. But au=
thors only fix their drafts when they have time or when there is deadline=
 pressure. There's no direction from above, only requests. And as others =
have said, *nothing* is a "standard" or even a "draft standard" until it =
is duly approved and published as an RFC with an RFC number. (Since you m=
entioned that you are new to our lists, I suggest starting at https://www=
=2Eietf.org/about/participate/get-started/ for a detailed introduction.)

If people make early implementations based on drafts, bugs and vulnerabil=
ities are to be expected.

But there is more. I gather that you are referring to an issue in draft-i=
rtf-cfrg-bls-signature-04. That is not even an IETF draft; it's an IRTF d=
raft, apparently being discussed in an IRTF Research Group. So it is not =
even remotely under consideration to become an IETF standard, so raising =
an issue here is completely beside the point and can have no possible res=
ults.

But there is even more. The draft is more than 6 months old and has there=
fore formally expired. Its own text says so: "Internet-Drafts are draft d=
ocuments valid for a maximum of six months."

To be frank, anyone who runs code based on an expired research draft outs=
ide a testbed is asking for trouble. But since this is not an IETF issue,=
 we should probably end this thread now.

Regards
   Brian Carpenter

On 27-Apr-21 03:46, Quan Thoi Minh Nguyen wrote:
>=20
>=20
> On Mon, Apr 26, 2021 at 8:24 AM Salz, Rich <rsalz@akamai.com <mailto:rs=
alz@akamai.com>> wrote:
>=20
>       * It doesn't matter to you, but it does matter to other=C2=A0peop=
le like me. ____
>=20
>     __=C2=A0__
>=20
>     You have been told several times, by several people, that a draft i=
s not a standard.=C2=A0 No matter what vendors do, no matter what emails =
say about it. Even if the subject of the document says =E2=80=9CA Standar=
d BLS Mechanism,=E2=80=9D until it is an RFC it is not a standard.____
>=20
>     __=C2=A0__
>=20
>     People within the IETF often use the word standard in a number of w=
ays.=C2=A0 That doesn=E2=80=99t mean the document IS a standard.____
>=20
>     __=C2=A0__
>=20
>     I unmderstand this is frustrating to you, but just because some ven=
dors implemented a draft, and you found a bug, that doesn=E2=80=99t mean =
the draft authors have to push out an update immediately.
>=20
>=20
> Not immediately. I reported the bugs privately a long time ago by a res=
ponsible=C2=A0disclosure mechanism, no fixing action and then I reported =
it publicly, no fixing action,=C2=A0no time commitment. I have been repor=
ting security bugs many time (e.g. I reported most bugs (mine and on beha=
lf of other people) in https://github.com/google/wycheproof/blob/master/d=
oc/bugs.md), but this is the 1st time there is a strange deadlock. I unde=
rstand BLS Internet-Draft authors' perspectives and I understand librarie=
s authors' perspectives. I tried but failed in convincing everyone to com=
promise in moving and fixing it :(
>=20
>     There is a reason, after all, why the document is called a **draft*=
*____
>=20
>     __=C2=A0__
>=20

