Re: NomCom selection Fwd: Notification for draft-eastlake-rfc3797bis-00.txt

Donald Eastlake <d3e3e3@gmail.com> Thu, 11 May 2023 04:55 UTC

Return-Path: <d3e3e3@gmail.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5938EC1FB61A for <ietf@ietfa.amsl.com>; Wed, 10 May 2023 21:55:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.845
X-Spam-Level:
X-Spam-Status: No, score=-1.845 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ndfMMg409di6 for <ietf@ietfa.amsl.com>; Wed, 10 May 2023 21:55:00 -0700 (PDT)
Received: from mail-ej1-x631.google.com (mail-ej1-x631.google.com [IPv6:2a00:1450:4864:20::631]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 54360C072E6D for <ietf@ietf.org>; Wed, 10 May 2023 21:55:00 -0700 (PDT)
Received: by mail-ej1-x631.google.com with SMTP id a640c23a62f3a-959a3e2dd27so1436866166b.3 for <ietf@ietf.org>; Wed, 10 May 2023 21:55:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20221208; t=1683780899; x=1686372899; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=oZTi7csg2GbG+QO4Cv25J6q2ZY0MDHWqC477RXOJ6+I=; b=kkZ2aQKE/Pd/AVGdiK9Cq9WhdJPkdgA9wLOBfo9VwrB1sQZzVZXfiJRf+T4W6c61j+ 3tFPTMj+mb7zmnpIIOyxQ33E1PM+9bfKhuj3JCWc5mRj//njBZrkX+8kpCgYql58r0C/ gy4THmTNh05NWcICwueG0ktww2kdAnaER6m+8GE5Bn8x4yG/rzCu3/3cW9/H0w8vUV52 BMd/blyeJUJvO2ETJglbiGEFM3obPM4Fz08mEIN8kj5plva34mQ+/02XTRnpN3ZNwHTX Ir85IO/yzT5Izd7GYIse5cNHqI7Be/q44maiSnc0x1pWIRRPa3CPLpb3MIhq2b+KMICq ZLNw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1683780899; x=1686372899; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=oZTi7csg2GbG+QO4Cv25J6q2ZY0MDHWqC477RXOJ6+I=; b=HTtkDd8Zj2+cD4BarPvNXFaXzfv2ZidCYjzkaWXnvHVls8Jh90SgZQG6noOy5IAIPl ATon3TGeFv38b5vDh6odMj8WlEc1Vrq53mfKbwpHS+bBzmEmlsM0UzZ88oW6FW4h/ymy FvuecvQOg3I2beVC66ifCCxAlHyiYdwHXvPCAtuDk0tDm2WolOf50mWljBROWkjYtDcz T/+yeYDxw0eF/v3477W3ERGA7jiSZSW1Ud9AIsb+jPUBl0RnE11o2AONpSZUITt3fEZU leUGRmFvEqTBxytzB4SZSe4lJX9+e6l0nwHY/IP5u65R+AtH5YW9/Qvs+/XEpd6zdBvL L/aw==
X-Gm-Message-State: AC+VfDyz3JtVnp7x1khz2e8cQOpCiJMYQMh2/CLXcGK7y2FZDtMhmisI 9dyT1QOMsyyAFsBrZkEJyQpPjnllzK6DHxW8UeM=
X-Google-Smtp-Source: ACHHUZ5nwvq4+xM87S6F52G9vDQAkAGGOGyKojIw9b04PWeQD6P66M1OhNjCEy2GdfN47ENO5sQRy5aIGK1OQSn6rUA=
X-Received: by 2002:a17:906:ef0d:b0:94e:e9c1:1932 with SMTP id f13-20020a170906ef0d00b0094ee9c11932mr19008885ejs.43.1683780898414; Wed, 10 May 2023 21:54:58 -0700 (PDT)
MIME-Version: 1.0
References: <CAF4+nEHEUhGirTdmaTNxxWS-5FY5k+wthoMfHfW2AbF=-i5QtQ@mail.gmail.com> <159C3FAA-EDBA-40C7-B511-C90812B08A3F@akamai.com> <cac7defd-6ae3-2ad0-3e4c-47429986b13a@comcast.net> <F6D5E632-BDEC-4E55-91B2-A44709C5A851@akamai.com> <BY5PR11MB4196B23E474C971D8FF8A281B5659@BY5PR11MB4196.namprd11.prod.outlook.com> <fc392dbc-71fd-1758-4cc1-98956fce34e6@joelhalpern.com> <A4AF171A-EDDC-40EC-A38F-D373591A94CD@akamai.com> <BY5PR11MB41964D2326DEB85F8A55BACAB5659@BY5PR11MB4196.namprd11.prod.outlook.com> <B55760E8-D175-4D4A-8CC8-138C3F65D5EF@akamai.com> <19717b66-cd2c-2fdc-ff2e-69816c41b84e@comcast.net> <ZFxU4D1bFRMrKczJ@faui48e.informatik.uni-erlangen.de>
In-Reply-To: <ZFxU4D1bFRMrKczJ@faui48e.informatik.uni-erlangen.de>
From: Donald Eastlake <d3e3e3@gmail.com>
Date: Thu, 11 May 2023 00:54:46 -0400
Message-ID: <CAF4+nEHVTE5pJvVZnQuKps7v8vB555JC3upTFzK4CC5GaUHKKw@mail.gmail.com>
Subject: Re: NomCom selection Fwd: Notification for draft-eastlake-rfc3797bis-00.txt
To: Toerless Eckert <tte@cs.fau.de>
Cc: Michael StJohns <mstjohns@comcast.net>, ietf@ietf.org
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/amsyWeIlb9BGnVLsBJP5MP_nK3Y>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "IETF-Discussion. This is the most general IETF mailing list, intended for discussion of technical, procedural, operational, and other topics for which no dedicated mailing lists exist." <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 May 2023 04:55:04 -0000

On Wed, May 10, 2023 at 10:37 PM Toerless Eckert <tte@cs.fau.de> wrote:
>
> It seems as if the concerns about added delay could indeed be eliminated for
> all practical purposes if we could find a random source that publishes
> future randomn numbers in short intervals (hourly ?!)  - and keeps them published for
> a sufficient long period for verification.

The other substantial component of the delay is the time it takes for
the Nomcom Chair to make a reasonable effort to contact the new
tentatively selected person or persons and determine if they are
actually contactable and are still willing to serve.

> I am not so sure that i would want to trust the independent randomness of some
> strage URL like https://api3.drand.sh though.

I would say it is most important for the public to have a reasonable
level of trust in the randomness so any cute technical place producing
frequent random numbers but which the public has never heard of does
not, in my opinion, qualify.

> Aka: It would also be lovely to pick a random source that we all feel is likely
> to be around for some decades unchanged.

Why would we specify the exact source? We never have before. We
specify the desirable criteria for the source and the Nomcom Chair
picks the source/sources.

Thanks,
Donald
===============================
 Donald E. Eastlake 3rd   +1-508-333-2270 (cell)
 2386 Panoramic Circle, Apopka, FL 32703 USA
 d3e3e3@gmail.com

> Cheers
>     Toerless
>
> On Fri, Apr 28, 2023 at 03:06:13PM -0400, Michael StJohns wrote:
> > On 4/26/2023 1:49 PM, Salz, Rich wrote:
> > > Does anyone disagree with the following?
> > > - 8713 will not be updated in time to take effect for this NomCom's selection process.
> > > - The text of 8713 specifies a process that, if followed, means a delay of at least one week, and perhaps at least two weeks.
> > >
> > > "Picking next one the list" is the process recommended by at least the last half-dozen NomCom chairs, and followed by at least one of them (me); perhaps more than one. Yes, this can be gamed.  So what; security is about trade-offs and saving time is more important for now.
> > >
> > > Some folks might want to review the errata athttps://www.rfc-editor.org/errata/rfc8713. I have no idea where discussions of that should happen.
> > >
> > > It wasn't clear to me if Rob was proposing an interpretation of 8713, or providing input to a revision.
> > >
> > > I had to disqualify one potential volunteer. They said yes, and then I was unable to interact with them for the next three days (it was the weekend).  One day is not enough. And weekends aren't the same globally, once you allow for timezones or countries that observe the classic Sabbath.
> > >
> > >
> >
> > I actually disagree.
> >
> > 4.16 requires that you announce the list and the selection method ahead of
> > time.  It does not require that for each and every iteration except that
> > "The method must depend on random data whose value is not known or available
> > until the date on which the random selection will occur.".
> >
> > The phrase that you might be giving more weight to that necessary is "The
> > announcement should be made at least one week prior to the date on which the
> > random selection will occur." - note the "should" vs a must.     In any
> > event, you could consider that a requirement for the initial roll, but as
> > long as you meet the requirement that the random data is unknown in advance
> > you could announce a re-roll to occur in a half hour, as long as the
> > announcement makes it to the list prior to the roll.  See below for an
> > example.
> >
> > Requiring a re-roll is necessary in certain circumstances:  "A method is
> > unbiased if no one can influence its outcome in favor of a specific
> > outcome."  I think that applies in all circumstances if someone needs to be
> > replaced because the outcome of the replacement can be predicted.
> >
> >
> > Example using the league of randomness.  I'm proposing to use round 2909292
> > of the first chain (8990...b2ce) as the randomness for a future roll.
> >
> >
> > https://api3.drand.sh/chains
> >
> > >>>
> >
> > 0     "8990e7a9aaed2ffed73dbd7092123d6f289930540d7651336225dc172e51b2ce"
> > 1     "dbd506d6ef76e5f386f41c651dcb808c5bcbd75471cc4eafa3f4df7ad4e4c493"
> >
> > https://api3.drand.sh/8990e7a9aaed2ffed73dbd7092123d6f289930540d7651336225dc172e51b2ce/info
> >
> > >>>
> >
> > public_key "868f005eb8e6e4ca0a47c8a77ceaa5309a47978a7c71bc5cce96366b5d7a569937c529eeda66c7293784a9402801af31"
> >
> > period        30  --- 2 rounds per minute
> > genesis_time  1595431050
> > hash  "8990e7a9aaed2ffed73dbd7092123d6f289930540d7651336225dc172e51b2ce"
> > groupHash "176f93498eac9ca337150b46d21dd58673ea4e3581185f869672e59fa4cb390a"
> > schemeID      "pedersen-bls-chained"
> > metadata
> > beaconID      "default"
> >
> >
> > >>> Current round
> >
> > https://api3.drand.sh/8990e7a9aaed2ffed73dbd7092123d6f289930540d7651336225dc172e51b2ce/public/latest
> >
> > round         2909232
> > randomness
> > "1303dd35336091d56d95dff1c21acb11a25a4c1be66593dd8392a147a19ea231"
> > signature "b80ebdab37f95217694beb2d45b172f003f66bf027556b8ff09dc5faff68715727dfa12364d9e912366a95ceb8b2ab01161ebbf93f59631a4be3c17193e1012a4e15d704eda2ab37dd28947b8036ec9a9e9ae21d08ded75e1cb3fe168e85b465"
> >
> > previous_signature "99b23a8e422dbaab411db82b18cd23ffaa944c6a76d5792e09367505c2f763b9570e15ecb0248ae751bb87539823a863108f8fa30538fef397b753131d3b87e465d621d1f5dc1324791a565ce55d1ae0a4e6c0180b33c483449715b17548e8fd"
> >
> >
> > Current round was at (2909232 * 30) + 1595431050 -> 1,682,708,010 Fri Apr 28
> > 2023 14:53:30 GMT-0400 (Eastern Daylight Time)
> >
> > >>> Target round (30 minutes) = 60 +  2909232 => 2909292
> >
> > https://api3.drand.sh/8990e7a9aaed2ffed73dbd7092123d6f289930540d7651336225dc172e51b2ce/public/2909292
> >
> > Not available as of the time I'm writing this note - server appears to wait
> > until it is.
> >
> > Mike
> >
> >
> >
> >
>
> --
> ---
> tte@cs.fau.de
>