Early Review of draft-knodel-e2ee-definition-07
review-knodel-e2ee-definition-07-secdir-early-piper-2022-10-03-00
Request | Review of | draft-knodel-e2ee-definition |
---|---|---|
Requested revision | No specific revision (document currently at 11) | |
Type | Early Review | |
Team | Security Area Directorate (secdir) | |
Deadline | 2022-10-03 | |
Requested | 2022-09-25 | |
Requested by | Paul Wouters | |
Authors | Mallory Knodel , Sofia Celi , Olaf Kolkman , Gurshabad Grover | |
I-D last updated | 2022-10-03 | |
Completed reviews |
Secdir Early review of -07
by Derrell Piper
(diff)
Intdir Early review of -07 by Donald E. Eastlake 3rd (diff) Artart Early review of -07 by Henry S. Thompson (diff) Tsvart Telechat review of -07 by David L. Black (diff) |
|
Assignment | Reviewer | Derrell Piper |
State | Completed | |
Request | Early review on draft-knodel-e2ee-definition by Security Area Directorate Assigned | |
Posted at | https://mailarchive.ietf.org/arch/msg/secdir/ejbJx9Fx8L0DOHkYgJ6D5l5ZsCE | |
Reviewed revision | 07 (document currently at 11) | |
Result | Ready | |
Completed | 2022-10-03 |
review-knodel-e2ee-definition-07-secdir-early-piper-2022-10-03-00
I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. The summary of this review is: READY pg. 13, "Opensource" -> "Open source" pg. 14 "decicions" -> "decisions" This document provides a definition of what end-to-end encryption (e2ee) means with respect to existing Internet security mechanisms and protocols, and how the security properties provided by these mechanism and protocols align with user expectations around privacy and confidentiality in light of RFC8890 ("The Internet is for End Users"). It is an improvement on the previous version in that it strenghtens some requirements, i.e. upgrades some SHOULDs to MUSTs, and clarifies others as MAYs. As it notes in its Security Considerations: "Because some policy decisions may affect the security of the internet, a clear and shared definition of end to end encrypted communication is important in policy related discussions. This document aims to provide that clarity." I believe this document correctly captures IETF concensus on e2ee. Derrell