Skip to main content

Early Review of draft-knodel-e2ee-definition-07
review-knodel-e2ee-definition-07-secdir-early-piper-2022-10-03-00

Request Review of draft-knodel-e2ee-definition
Requested revision No specific revision (document currently at 11)
Type Early Review
Team Security Area Directorate (secdir)
Deadline 2022-10-03
Requested 2022-09-25
Requested by Paul Wouters
Authors Mallory Knodel , Sofia Celi , Olaf Kolkman , Gurshabad Grover
I-D last updated 2022-10-03
Completed reviews Secdir Early review of -07 by Derrell Piper (diff)
Intdir Early review of -07 by Donald E. Eastlake 3rd (diff)
Artart Early review of -07 by Henry S. Thompson (diff)
Tsvart Telechat review of -07 by David L. Black (diff)
Assignment Reviewer Derrell Piper
State Completed
Request Early review on draft-knodel-e2ee-definition by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/ejbJx9Fx8L0DOHkYgJ6D5l5ZsCE
Reviewed revision 07 (document currently at 11)
Result Ready
Completed 2022-10-03
review-knodel-e2ee-definition-07-secdir-early-piper-2022-10-03-00
I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the IESG.
These comments were written primarily for the benefit of the security
area directors.  Document editors and WG chairs should treat these
comments just like any other last call comments.

The summary of this review is: READY

pg. 13, "Opensource" -> "Open source"

pg. 14 "decicions" -> "decisions"

This document provides a definition of what end-to-end encryption (e2ee)
means with respect to existing Internet security mechanisms and
protocols, and how the security properties provided by these mechanism
and protocols align with user expectations around privacy and
confidentiality in light of RFC8890 ("The Internet is for End Users").

It is an improvement on the previous version in that it strenghtens some
requirements, i.e. upgrades some SHOULDs to MUSTs, and clarifies others
as MAYs.

As it notes in its Security Considerations: "Because some policy
decisions may affect the security of the internet, a clear and shared
definition of end to end encrypted communication is important in policy
related discussions.  This document aims to provide that clarity."

I believe this document correctly captures IETF concensus on e2ee.

Derrell