Re: [openpgp] ways forward wrt IETF wg - please try answer by Apr 8th

Benjamin Kaduk <kaduk@MIT.EDU> Wed, 08 April 2015 18:05 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CEC391A8928 for <openpgp@ietfa.amsl.com>; Wed, 8 Apr 2015 11:05:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aQVLC51HIW7f for <openpgp@ietfa.amsl.com>; Wed, 8 Apr 2015 11:05:47 -0700 (PDT)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7A4DD1A891F for <openpgp@ietf.org>; Wed, 8 Apr 2015 11:05:42 -0700 (PDT)
X-AuditID: 12074424-f79f56d000000da5-71-55256df5931f
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-7.mit.edu (Symantec Messaging Gateway) with SMTP id 2B.34.03493.5FD65255; Wed, 8 Apr 2015 14:05:41 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id t38I5eGS005243; Wed, 8 Apr 2015 14:05:40 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t38I5cSo010130 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 8 Apr 2015 14:05:39 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t38I5bOt021685; Wed, 8 Apr 2015 14:05:37 -0400 (EDT)
Date: Wed, 08 Apr 2015 14:05:37 -0400
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
In-Reply-To: <551C3FAD.6040107@cs.tcd.ie>
Message-ID: <alpine.GSO.1.10.1504081356590.22210@multics.mit.edu>
References: <551C3FAD.6040107@cs.tcd.ie>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrDIsWRmVeSWpSXmKPExsUixCmqrPs1VzXU4HanhEXDv4fsFtP3XmN3 YPJY232VzWPJkp9MAUxRXDYpqTmZZalF+nYJXBlHdzYyFSzjqXh0PKeB8SJnFyMnh4SAicT/ rfeZIGwxiQv31rN1MXJxCAksZpKY9WwnM4SzgVFi4fs2VgjnIJPE1C8TmEFahATqJVrn3GUE sVkEtCR+vbsCNopNQEVi5puNbCC2iIC+xN7N59hBbGYBTYkX56aC9QoLBEhcXzmVFcTmBIo3 /+ljAbF5BRwl7t14yggxX0Ni1Y7tYL2iAjoSq/dPgaoRlDg58wkLxEwtieXTt7FMYBSchSQ1 C0lqASPTKkbZlNwq3dzEzJzi1GTd4uTEvLzUIl1zvdzMEr3UlNJNjKBAZXdR2cHYfEjpEKMA B6MSD6/AYpVQIdbEsuLK3EOMkhxMSqK8kcmqoUJ8SfkplRmJxRnxRaU5qcWHGCU4mJVEeLNA crwpiZVVqUX5MClpDhYlcd5NP/hChATSE0tSs1NTC1KLYLIyHBxKErzywIgUEixKTU+tSMvM KUFIM3FwggznARp+KwdkeHFBYm5xZjpE/hSjopQ47ySQhABIIqM0D64XlkheMYoDvSLMGwVS xQNMQnDdr4AGMwEN5n+mBDK4JBEhJdXA2J4QkBPR5xry+kYFe7/UxfnfZy8TcvNefL/S5HDT rOCgw3vOH/z3+nHavrqX6iVVmgd3Sun8ja2dZJxZ9/HFrohg75TD0feyPNmTl7jGrM6+VN1X t+1/jEd+qtz0mUaGMt9+vgkOvxa51TwxNIqXRWK5+ZNNj92Pb/q6zt0m1OPyl10/j7w0VmIp zkg01GIuKk4EAM1phxn/AgAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/openpgp/4zUPCTwWtXchpfYrIrBOyFrENwc>
Cc: "openpgp@ietf.org" <openpgp@ietf.org>
Subject: Re: [openpgp] ways forward wrt IETF wg - please try answer by Apr 8th
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 08 Apr 2015 18:05:49 -0000

Nothing like a deadline to motivate replies...

On Wed, 1 Apr 2015, Stephen Farrell wrote:

> It would also really help me (and I suspect others) evaluate
> messages if you could say something about how you fit into
> the openpgp universe (e.g. "I wrote the foo implementation"
> or "I run a thing with N people using pgp" or whatever). An
> essay on that is not useful here, but a line or two could
> be really good.

I consume PGP for encrypted discussion of embargoed security issues, e.g.,
in my role as a maintainer of MIT Kerberos.

> Anyway here's the options:
>
> option 1: do nothing - there's nothing much to do or at least
>
> option 2: do maintenance work on rfc4880 - produce a 4880bis
>
> option 3: do a major revision to openpgp - take rfc4880 as a
> starting point but question all design decisions in the process
>
> option 4: move beyond openpgp (or smime) to develop a new
> flavour of end-to-end security for interpersonal messaging,
>
I think 2 is the most feasible so far, and we could get agreement on what
to do without too much teeth-gnashing.  Option 3 is tempting, but it may
be a larger project than there is energy to take on.  Option 4 seems like
it ought to be a new working group (and is additionally unlikely to gain
much adoption barring a bit player pushing it to users), so I don't think
we should tackle it here.

I also would prefer to not try to mandate a specific trust model or
models, though we can certainly have some in mind to ensure that what we
come up with is compatible with them.

-Ben