Re: [openpgp] Partial review of the crypto refresh

Paul Wouters <paul@nohats.ca> Thu, 24 November 2022 15:58 UTC

Return-Path: <paul@nohats.ca>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 40F0BC14F734 for <openpgp@ietfa.amsl.com>; Thu, 24 Nov 2022 07:58:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.095
X-Spam-Level:
X-Spam-Status: No, score=-7.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nohats.ca
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z-89x2WMl7wI for <openpgp@ietfa.amsl.com>; Thu, 24 Nov 2022 07:58:28 -0800 (PST)
Received: from mx.nohats.ca (mx.nohats.ca [IPv6:2a03:6000:1004:1::85]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 57D1AC14F72F for <openpgp@ietf.org>; Thu, 24 Nov 2022 07:58:28 -0800 (PST)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 4NJ2hx1CmJzCKR for <openpgp@ietf.org>; Thu, 24 Nov 2022 16:58:25 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1669305505; bh=nm9fESbE6KbXNIKSu0elgWgvEcS/BdJ0GC4MX/pkNTY=; h=Date:From:To:Subject:In-Reply-To:References; b=mJuz9W6fTIgkcOPCbsBFsMQGg+vyblexgKq7ycoqH2xFp9F4uqMVauIED9mF23aqo 4XLB7X0FkkV/Vn5vJCTJd/UZxKq5KjNr3srl/hHI9jirwlZLjP7Poj7gBNFg5OybJM gcKi6eoeKwgrfJeXS4xF8HMuDOn9w+QSgDDnd7N0=
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id DeVJLmQZAkqY for <openpgp@ietf.org>; Thu, 24 Nov 2022 16:58:23 +0100 (CET)
Received: from bofh.nohats.ca (bofh.nohats.ca [193.110.157.194]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS for <openpgp@ietf.org>; Thu, 24 Nov 2022 16:58:23 +0100 (CET)
Received: by bofh.nohats.ca (Postfix, from userid 1000) id 331F241130E; Thu, 24 Nov 2022 10:58:22 -0500 (EST)
Received: from localhost (localhost [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id 2FFF441130D for <openpgp@ietf.org>; Thu, 24 Nov 2022 10:58:22 -0500 (EST)
Date: Thu, 24 Nov 2022 10:58:22 -0500
From: Paul Wouters <paul@nohats.ca>
To: IETF OpenPGP WG <openpgp@ietf.org>
In-Reply-To: <F3DD8D6F-A421-434D-9073-5CD3109421DA@andrewg.com>
Message-ID: <de5bde12-fcf3-819e-3c0f-058eff057067@nohats.ca>
References: <HniDSkOrqQhzJeIb0B_7yLgQjsIDVZZdGPnwttTdfpk4LCN7B4Nh1J6xzv1eZIV-OR6UemykSEdao4pWe5gFfr5BUWhEfHX8mdj6Jhla6xg=@protonmail.com> <F3DD8D6F-A421-434D-9073-5CD3109421DA@andrewg.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/YY62fV0LwQyvAf-HTLAtkv9x0Xc>
Subject: Re: [openpgp] Partial review of the crypto refresh
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Nov 2022 15:58:33 -0000

On Thu, 24 Nov 2022, Andrew Gallagher wrote:

[speaking as individul]

>               *  Some technologies mentioned here may be subject to government
>                  control in some countries.
>
>       Is this still true? Can this be removed?
> 
> IMO this should be kept in. Even if it is not currently true, it may become true again during the lifetime of this standard.

What is the goal of the statement? I don't see a value in it. It very
much feels like "may contain traces of peanuts".

We do not add these disclaimers to TLS or IPsec or any of the
cryprographic algorithms documents we publish at the IETF.

I would also be in favour of removing it.

Paul