[{"author": "Deb Cooley", "text": "<p>Happy Friday!</p>", "time": "2025-07-25T07:31:54Z"}, {"author": "Deb Cooley", "text": "<p>Any one interested in taking notes?</p>", "time": "2025-07-25T07:32:02Z"}, {"author": "Mike Ounsworth", "text": "<p>Ok. Consider my arm twisted.</p>", "time": "2025-07-25T07:33:25Z"}, {"author": "Deb Cooley", "text": "<p>yay, TYVM!!!</p>", "time": "2025-07-25T07:33:45Z"}, {"author": "Leif Johansson", "text": "<p>Like a phone?</p>", "time": "2025-07-25T07:34:05Z"}, {"author": "Quynh Dang", "text": "<p>there is a side meeting for NTRU after SAAG. Does someone know the room for it ? Thank you in advance.</p>", "time": "2025-07-25T07:34:37Z"}, {"author": "Deb Cooley", "text": "<p>@Quynh:  there are only two options</p>", "time": "2025-07-25T07:35:15Z"}, {"author": "Mike Ounsworth", "text": "<p><span class=\"user-mention\" data-user-id=\"380\">@Quynh Dang</span> The side-meeting schedule is here: <a href=\"https://trello.com/b/6kmZPwOx/ietf-123-side-meeting-scheduling\">https://trello.com/b/6kmZPwOx/ietf-123-side-meeting-scheduling</a></p>", "time": "2025-07-25T07:36:12Z"}, {"author": "Muhammad Usama Sardar", "text": "<p>@Quynh: It is in Segovia. <a href=\"https://trello.com/c/Tmn8Xymi\">https://trello.com/c/Tmn8Xymi</a></p>", "time": "2025-07-25T07:39:10Z"}, {"author": "Martin Thomson", "text": "<p>Looking for rapid unplanned disassembly of working groups</p>", "time": "2025-07-25T07:39:11Z"}, {"author": "Richard Barnes", "text": "<p>As opposed to the planned disassembly of HPKE</p>", "time": "2025-07-25T07:41:25Z"}, {"author": "Kathleen Moriarty", "text": "<p>Any of the former SecADs, including me, are more than happy to answer questions if interested in serving in this important role for the community. Stephen, Sean, Russ, and I are all in person. I am sure others would be okay for you to reach out to them as well!</p>", "time": "2025-07-25T07:41:33Z"}, {"author": "Mike Ounsworth", "text": "<p><span class=\"user-mention\" data-user-id=\"416\">@Nancy Cam-Winget</span> what is the document you wanted to call out?</p>", "time": "2025-07-25T07:43:01Z"}, {"author": "Stephen Farrell", "text": "<p>@mike: scim architecture or something like that</p>", "time": "2025-07-25T07:43:50Z"}, {"author": "Deb Cooley", "text": "<p>scim use cases</p>", "time": "2025-07-25T07:44:06Z"}, {"author": "Nancy Cam-Winget", "text": "<p>@Mike Ounsworth the draft is <a href=\"https://datatracker.ietf.org/doc/draft-ietf-scim-device-model/\">https://datatracker.ietf.org/doc/draft-ietf-scim-device-model/</a>  for interoperability and the other is <a href=\"https://www.ietf.org/archive/id/draft-correia-scimusecases-00.html\">https://www.ietf.org/archive/id/draft-correia-scimusecases-00.html</a></p>", "time": "2025-07-25T07:44:41Z"}, {"author": "David Benjamin", "text": "<p>I'm very pleased with the PLANTS backronym we ended up with. :-D</p>", "time": "2025-07-25T07:46:09Z"}, {"author": "David Benjamin", "text": "<p>(Slightly unclear if the list ended up being PLANT or PLANTS. If we accidentally lose the S, I guess s/Tree Signatures/Trees/, whatever.)</p>", "time": "2025-07-25T07:47:23Z"}, {"author": "Deb Cooley", "text": "<p>maybe only one tree?</p>", "time": "2025-07-25T07:47:41Z"}, {"author": "Daniel Gillmor", "text": "<p>Phillip, please take a look at <a href=\"https://github.com/autocrypt/autocrypt/pull/456\">https://github.com/autocrypt/autocrypt/pull/456</a> (folks working on OpenPGP certificates in vCards)</p>", "time": "2025-07-25T07:47:43Z"}, {"author": "Richard Barnes", "text": "<p>overachievers in LAMPS</p>", "time": "2025-07-25T07:48:02Z"}, {"author": "Stephen Farrell", "text": "<p>closr LAMPS:-)</p>", "time": "2025-07-25T07:48:15Z"}, {"author": "Richard Barnes", "text": "<p>what is a \"page\"?</p>", "time": "2025-07-25T07:48:25Z"}, {"author": "Daniel Gillmor", "text": "<p>@David, SETTLE ends in a word that doesn't start with an E also, don't feel bad</p>", "time": "2025-07-25T07:48:33Z"}, {"author": "Martin Thomson", "text": "<p>What does the L stand for again?</p>", "time": "2025-07-25T07:48:40Z"}, {"author": "Nicola Tuveri", "text": "<p>How many of those are Mike\u2019s fault?</p>", "time": "2025-07-25T07:48:44Z"}, {"author": "Mike Ounsworth", "text": "<p><span class=\"user-mention silent\" data-user-id=\"26\">Martin Thomson</span> <a href=\"#narrow/channel/337-saag/topic/ietf-123/near/177662\">said</a>:</p>\n<blockquote>\n<p>What does the L stand for again?</p>\n</blockquote>\n<p>\"Lots of\"</p>", "time": "2025-07-25T07:48:59Z"}, {"author": "Deb Cooley", "text": "<p>which Mike?</p>", "time": "2025-07-25T07:48:59Z"}, {"author": "Ben S", "text": "<p><span class=\"user-mention silent\" data-user-id=\"26\">Martin Thomson</span> <a href=\"#narrow/channel/337-saag/topic/ietf-123/near/177662\">said</a>:</p>\n<blockquote>\n<p>What does the L stand for again?</p>\n</blockquote>\n<p>Limitless</p>", "time": "2025-07-25T07:49:12Z"}, {"author": "Richard Barnes", "text": "<p>SETTLE should have been SAILOR ~ Secure Access to Internal / LOcal Resources</p>", "time": "2025-07-25T07:49:19Z"}, {"author": "David Benjamin", "text": "<p>Pffft, we needed almost no shenanigans with PLANTS. \"And\" just contributes two letters. (PKI, Logs, ANd, Tree Signatures)</p>", "time": "2025-07-25T07:49:28Z"}, {"author": "Richard Barnes", "text": "<p><span class=\"user-mention\" data-user-id=\"829\">@David Benjamin</span> no \"Pffft\" was a different bof this week</p>", "time": "2025-07-25T07:50:06Z"}, {"author": "Nicola Tuveri", "text": "<p>@Deb the right Mike knows! <span aria-label=\"rolling on the floor laughing\" class=\"emoji emoji-1f923\" role=\"img\" title=\"rolling on the floor laughing\">:rolling_on_the_floor_laughing:</span></p>", "time": "2025-07-25T07:50:20Z"}, {"author": "Martin Thomson", "text": "<p><span aria-label=\"potato\" class=\"emoji emoji-1f954\" role=\"img\" title=\"potato\">:potato:</span></p>", "time": "2025-07-25T07:50:27Z"}, {"author": "Richard Barnes", "text": "<p>i 100% came to secdir lunch just for the food</p>", "time": "2025-07-25T07:50:55Z"}, {"author": "Richard Barnes", "text": "<p>Hotel Secdir</p>", "time": "2025-07-25T07:51:12Z"}, {"author": "Robert Moskowitz", "text": "<p>Need hot food to get to hot topics?</p>", "time": "2025-07-25T07:51:13Z"}, {"author": "Deb Cooley", "text": "<p>I did request '<a href=\"mailto:plants@ietf.org\">plants@ietf.org</a>'.... so it is just a local error on the saag slides</p>", "time": "2025-07-25T07:51:38Z"}, {"author": "Martin Thomson", "text": "<p>Huh, I've somehow avoided SECDIR for the entire time I've been at the IETF.  And that remains, despite chairing two SEC groups.</p>", "time": "2025-07-25T07:51:54Z"}, {"author": "Martin Thomson", "text": "<p>I didn't realize that chairing qualified</p>", "time": "2025-07-25T07:52:12Z"}, {"author": "David Benjamin", "text": "<p>Ah great. (Either would have been fine. Just wasn't sure which. <span aria-label=\"smile\" class=\"emoji emoji-1f642\" role=\"img\" title=\"smile\">:smile:</span> )</p>", "time": "2025-07-25T07:52:15Z"}, {"author": "Deb Cooley", "text": "<p>we can add you <span aria-label=\"grinning\" class=\"emoji emoji-1f600\" role=\"img\" title=\"grinning\">:grinning:</span></p>", "time": "2025-07-25T07:52:18Z"}, {"author": "Deb Cooley", "text": "<p>if you want more work</p>", "time": "2025-07-25T07:52:25Z"}, {"author": "Daniel Gillmor", "text": "<p>what's the difference between \"not ready\" and \"serious issues\"?</p>", "time": "2025-07-25T07:52:28Z"}, {"author": "Martin Thomson", "text": "<p>Don't put yourself out Deb</p>", "time": "2025-07-25T07:52:30Z"}, {"author": "Martin Thomson", "text": "<p>March was great.</p>", "time": "2025-07-25T07:52:56Z"}, {"author": "Stephen Farrell", "text": "<p>@dkg: they're different buttons</p>", "time": "2025-07-25T07:52:59Z"}, {"author": "Deb Cooley", "text": "<p>@DKG:  do you want that addressed at the mic?</p>", "time": "2025-07-25T07:53:05Z"}, {"author": "Daniel Gillmor", "text": "<p>meh <span aria-label=\"shrug\" class=\"emoji emoji-1f937\" role=\"img\" title=\"shrug\">:shrug:</span></p>", "time": "2025-07-25T07:53:32Z"}, {"author": "Paul Wouters", "text": "<p>dkg: it is kinda up to the reviewer. I agree there is some overlap there.</p>", "time": "2025-07-25T07:56:36Z"}, {"author": "Paul Wouters", "text": "<p>MT: We will fix that for you</p>", "time": "2025-07-25T07:57:11Z"}, {"author": "Dan Harkins", "text": "<p>I would say \"serious issues\" &gt;&gt; \"not ready\". A document can be not ready for reasons that might not be serious.</p>", "time": "2025-07-25T07:58:48Z"}, {"author": "Jim Fenton", "text": "<p>dig: I think of \u201cnot ready\u201d as meaning it needs more work, while \u201cserious issues\u201d implies it may be going in the wrong direction</p>", "time": "2025-07-25T07:58:55Z"}, {"author": "Paul Wouters", "text": "<p>Thanks Katheeln and other former SEC ADs for offering insights into the SEC AD role</p>", "time": "2025-07-25T07:59:14Z"}, {"author": "Richard Barnes", "text": "<p><a href=\"/user_uploads/2/9d/s49r-9ay2n7yfz3nCA3trBoK/image.png\">image.png</a></p>\n<div class=\"message_inline_image\"><a href=\"/user_uploads/2/9d/s49r-9ay2n7yfz3nCA3trBoK/image.png\" title=\"image.png\"><img data-original-content-type=\"image/png\" data-original-dimensions=\"700x706\" src=\"/user_uploads/thumbnail/2/9d/s49r-9ay2n7yfz3nCA3trBoK/image.png/840x560.webp\"></a></div>", "time": "2025-07-25T08:02:17Z"}, {"author": "Martin Thomson", "text": "<p>I'm struggling with this.  The HTTP usage is not really consistent with HTTP generally.  It seems like WebSockets is fine.</p>", "time": "2025-07-25T08:05:44Z"}, {"author": "Martin Thomson", "text": "<p>Thanks Dr Doolittle.</p>", "time": "2025-07-25T08:05:57Z"}, {"author": "Deb Cooley", "text": "<p>@MT do you have time to review?</p>", "time": "2025-07-25T08:06:35Z"}, {"author": "Martin Thomson", "text": "<p>See above.</p>", "time": "2025-07-25T08:06:43Z"}, {"author": "Deb Cooley", "text": "<p>TY</p>", "time": "2025-07-25T08:06:53Z"}, {"author": "Martin Thomson", "text": "<p>HTTP is a request response protocol.  You can't just put requests and responses whereever you like.</p>", "time": "2025-07-25T08:07:29Z"}, {"author": "Martin Thomson", "text": "<p>I mean, you <em>can</em>, but you really shouldn't.</p>", "time": "2025-07-25T08:07:37Z"}, {"author": "Richard Barnes", "text": "<p><span aria-label=\"potato\" class=\"emoji emoji-1f954\" role=\"img\" title=\"potato\">:potato:</span> <span aria-label=\"potato\" class=\"emoji emoji-1f954\" role=\"img\" title=\"potato\">:potato:</span> <span aria-label=\"potato\" class=\"emoji emoji-1f954\" role=\"img\" title=\"potato\">:potato:</span></p>", "time": "2025-07-25T08:07:45Z"}, {"author": "Martin Thomson", "text": "<p>I don't see why you can't POST (sets of) SETs in normal requests.</p>", "time": "2025-07-25T08:08:45Z"}, {"author": "Stephen Farrell", "text": "<p>I do think RFC 4086 could do with an update and that ought include what's in <a href=\"https://datatracker.ietf.org/doc/html/rfc8446#appendix-C.1\">https://datatracker.ietf.org/doc/html/rfc8446#appendix-C.1</a></p>", "time": "2025-07-25T08:09:52Z"}, {"author": "Martin Thomson", "text": "<p>Also, batching requests adds complexity.  We have HTTP things for reducing overhead on multiple requests.</p>", "time": "2025-07-25T08:09:55Z"}, {"author": "Deb Cooley", "text": "<p>TY, I've added that to the notes (so I can find it again later)</p>", "time": "2025-07-25T08:10:54Z"}, {"author": "Daniel Gillmor", "text": "<p><a href=\"https://www.rfc-editor.org/rfc/rfc9580.html#name-random-number-generation-an\">https://www.rfc-editor.org/rfc/rfc9580.html#name-random-number-generation-an</a> has more discussion in addition to referencing RFC 4086</p>", "time": "2025-07-25T08:10:57Z"}, {"author": "Martin Thomson", "text": "<p>4086 could be replaced with a much shorter note.</p>", "time": "2025-07-25T08:11:24Z"}, {"author": "Stephen Farrell", "text": "<p>could well be shorter nowadays</p>", "time": "2025-07-25T08:11:36Z"}, {"author": "Daniel Gillmor", "text": "<p>please also do <em>not</em> recommend /dev/random or /dev/urandom.</p>", "time": "2025-07-25T08:12:26Z"}, {"author": "Daniel Gillmor", "text": "<p>on modern unix systems there is a getrandom() syscall which is better</p>", "time": "2025-07-25T08:12:54Z"}, {"author": "Rich Salz", "text": "<p>Disagree strongly with Paul; this is <em>not</em> for the SEC area folks.</p>", "time": "2025-07-25T08:12:56Z"}, {"author": "Stephen Farrell", "text": "<p>I really would like it to reference dual-ec :-)</p>", "time": "2025-07-25T08:13:08Z"}, {"author": "Deb Cooley", "text": "<p>It is for security considerations.</p>", "time": "2025-07-25T08:13:12Z"}, {"author": "Dan Harkins", "text": "<p>@Stephen, if the points are generated using fixed strings and hash-to-curve, dual_ec would be great.</p>", "time": "2025-07-25T08:13:49Z"}, {"author": "Martin Thomson", "text": "<p>I'd like a document that makes it clear that the point of randomness is that it is <em>unpredictable</em> and that sometimes you can use a PRF or PRG if your reasons for seeking unpredictability is limited toward certain (other) entities</p>", "time": "2025-07-25T08:14:10Z"}, {"author": "Jim Fenton", "text": "<p>SP 800-90 has gotten a lot more complicated, with 800-90A, 800-90B, and 800-90C now</p>", "time": "2025-07-25T08:14:12Z"}, {"author": "Sean Turner", "text": "<p>Donald said he was willing to do he leg work so let's take him up on it!</p>", "time": "2025-07-25T08:14:18Z"}, {"author": "Martin Thomson", "text": "<p>This does not need to be a manual on how to build an RNG.  It needs to be a manual for those seeking randomness.</p>", "time": "2025-07-25T08:16:12Z"}, {"author": "Deb Cooley", "text": "<p>exactly</p>", "time": "2025-07-25T08:16:23Z"}, {"author": "Sean Turner", "text": "<p>+1 to what MT said</p>", "time": "2025-07-25T08:16:27Z"}, {"author": "Stephen Farrell", "text": "<p>+1 mt</p>", "time": "2025-07-25T08:16:30Z"}, {"author": "Paul Hoffman", "text": "<p>+1 mt</p>", "time": "2025-07-25T08:16:40Z"}, {"author": "Daniel Gillmor", "text": "<p>+1 mt</p>", "time": "2025-07-25T08:16:44Z"}, {"author": "Tapio Sokura", "text": "<p>If RFC 4086 is badly out of date and not good advice anymore, it could just be marked historic now. No matter if an updated RFC ever comes out.</p>", "time": "2025-07-25T08:18:58Z"}, {"author": "Paul Hoffman", "text": "<p>A document that says \"you should be sure that $x\" where the reader can't be sure is actively harmful.</p>", "time": "2025-07-25T08:18:59Z"}, {"author": "Martin Thomson", "text": "<p>I think that I'd prefer obsolescence to making 4086 historic</p>", "time": "2025-07-25T08:20:06Z"}, {"author": "Tapio Sokura", "text": "<p>+1 mt</p>", "time": "2025-07-25T08:20:10Z"}, {"author": "Stephen Farrell", "text": "<p>the checkoway reference would also be a good one to add and maybe even synopsise in a para: <a href=\"https://eprint.iacr.org/2016/376.pdf\">https://eprint.iacr.org/2016/376.pdf</a></p>", "time": "2025-07-25T08:20:24Z"}, {"author": "Tapio Sokura", "text": "<p>The \"seeking randomness\" thing :)</p>", "time": "2025-07-25T08:20:34Z"}, {"author": "Stephen Farrell", "text": "<p>we need a ramdon mesh!</p>", "time": "2025-07-25T08:21:06Z"}, {"author": "Daniel Gillmor", "text": "<p>@phil, that's not always true.  sometimes you publish your randomness.  you don't want unguessability, you want unpredictability.</p>", "time": "2025-07-25T08:21:37Z"}, {"author": "Alan DeKok", "text": "<p>unguessability, unpredictability, and a good distribution?</p>", "time": "2025-07-25T08:22:09Z"}, {"author": "Deb Cooley", "text": "<p>and sometimes you just need it to be different - IVs</p>", "time": "2025-07-25T08:22:12Z"}, {"author": "Robert Moskowitz", "text": "<p>Modern operating systems may not be enough.  Way back in IEEE 802.11i, we had to advise how to create randomness within an isolated component.  We recommended a set of ring oscillators.</p>", "time": "2025-07-25T08:22:17Z"}, {"author": "Martin Thomson", "text": "<p>uniform distributions are almost always sufficient</p>", "time": "2025-07-25T08:22:28Z"}, {"author": "Martin Thomson", "text": "<p>though not for DP, sadly</p>", "time": "2025-07-25T08:22:44Z"}, {"author": "Rich Salz", "text": "<p>@Robert: I'm thinking \"modern\" is the past 10 years; when are you talking about?</p>", "time": "2025-07-25T08:23:02Z"}, {"author": "Thom Wiggers", "text": "<p>Please tell us about the animals</p>", "time": "2025-07-25T08:23:03Z"}, {"author": "Daniel Gillmor", "text": "<p>@Thom, this is the section where they let us out of the crate</p>", "time": "2025-07-25T08:23:19Z"}, {"author": "Deb Cooley", "text": "<p>that's my Hansel and Gretel.  Hansel is the cat, who raised Gretel, the dog.</p>", "time": "2025-07-25T08:23:38Z"}, {"author": "Deb Cooley", "text": "<p>Gretel is now 3 YO and much larger.</p>", "time": "2025-07-25T08:23:50Z"}, {"author": "Deb Cooley", "text": "<p>She still defers to Hansel.</p>", "time": "2025-07-25T08:24:00Z"}, {"author": "Thom Wiggers", "text": "<p>More relevant to the \u201chow to do PRNG\u201d discussion there may be some things w can learn from how Jason Donenfeld cleaned up RNG in Linux</p>", "time": "2025-07-25T08:24:21Z"}, {"author": "Thom Wiggers", "text": "<p>Deb: &lt;3</p>", "time": "2025-07-25T08:24:32Z"}, {"author": "Jeff Lombardo", "text": "<p>You can only defer to retractable sharpened claws</p>", "time": "2025-07-25T08:24:38Z"}, {"author": "Dan Harkins", "text": "<p>just what we need new legal requirements for doing security</p>", "time": "2025-07-25T08:24:47Z"}, {"author": "Rich Salz", "text": "<p>Can we get bellingcat to analyze Deb's picture? :)</p>", "time": "2025-07-25T08:25:44Z"}, {"author": "Ben S", "text": "<p>Can we nominate Hansel for Sec AD?</p>", "time": "2025-07-25T08:26:42Z"}, {"author": "Stephen Farrell", "text": "<p>it would be good if the sec ads tried find a victim^Wvolunteer willing to take part in that Eu thing (note: it won't be me:-)</p>", "time": "2025-07-25T08:26:53Z"}, {"author": "Deb Cooley", "text": "<p>he does already come to telechats</p>", "time": "2025-07-25T08:26:59Z"}, {"author": "Daniel Gillmor", "text": "<p><a href=\"https://ec.europa.eu/transparency/expert-groups-register/screen/expert-groups/consult?lang=en&amp;groupID=4005\">https://ec.europa.eu/transparency/expert-groups-register/screen/expert-groups/consult?lang=en&amp;groupID=4005</a></p>", "time": "2025-07-25T08:27:09Z"}, {"author": "Rich Salz", "text": "<p>I am confused about what the points are that Rudiger is trying to make.</p>", "time": "2025-07-25T08:27:41Z"}, {"author": "Stephen Farrell", "text": "<p>IIUC it's unpaid and from expereience requires filling in a lot of forms</p>", "time": "2025-07-25T08:27:45Z"}, {"author": "Robert Moskowitz", "text": "<p>@Rich, that was 23 years ago.  But the point was the OS rand was not available to the MAC adapter code.  It was the adapter firmware that needed the rand, so it needed its own source.</p>", "time": "2025-07-25T08:27:56Z"}, {"author": "Stephen Farrell", "text": "<p>@rich: the EU are forming some multistakeholder \"expert\" groups to advise about NIS2 details - not clear to me if it's a fig-leaf or not</p>", "time": "2025-07-25T08:28:26Z"}, {"author": "Rich Salz", "text": "<p>Tnx Bob/Stephen</p>", "time": "2025-07-25T08:28:41Z"}, {"author": "Stephen Farrell", "text": "<p>NIS2 in theory could've required anyone with a \"DNS server\" to register/do-stuff, then somene told 'em about stubs:-)</p>", "time": "2025-07-25T08:29:09Z"}, {"author": "Rich Salz", "text": "<p>Way to drive the analogy into the ground, Bas!!</p>", "time": "2025-07-25T08:29:41Z"}, {"author": "Robert Moskowitz", "text": "<p>Bye all.  See you in Montreal!</p>", "time": "2025-07-25T08:30:09Z"}, {"author": "Henk Birkholz", "text": "<p>Bye Bob!</p>", "time": "2025-07-25T08:30:26Z"}]