[{"author": "Michael Jones", "text": "<p>Thie minutes should probably record that Tiru's audio is largely unintelligible</p>", "time": "2025-11-05T14:47:23.000Z"}, {"author": "Michael Jones", "text": "<p>It's not the meetecho setup because Filip's audio is perfect</p>", "time": "2025-11-05T14:47:36.000Z"}, {"author": "Mike Ounsworth", "text": "<p>@Tiru, @Filip -- as note-taker, I was not able to capture that discussion at all. Can you both please add your points to the minutes?</p>", "time": "2025-11-05T14:47:51.000Z"}, {"author": "Michael Jones", "text": "<p>But anything that Tiru intends to convey should probably be repeated on the mailing list</p>", "time": "2025-11-05T14:47:52.000Z"}, {"author": "Filip Skokan", "text": "<p>audio from Tiru is really bad i can barely follow along</p>", "time": "2025-11-05T14:48:13.000Z"}, {"author": "Michael Jones", "text": "<p>Filip, that's true in the room too.  Like I said, anything Tiru intends to communicate probably needs to be sent to the mailing list.</p>", "time": "2025-11-05T14:49:44.000Z"}, {"author": "Brian Campbell", "text": "<p>the alg is in the message in JOSE</p>", "time": "2025-11-05T14:53:01.000Z"}, {"author": "Brian Campbell", "text": "<p>it is</p>", "time": "2025-11-05T14:53:04.000Z"}, {"author": "Brian Campbell", "text": "<p>good or bad</p>", "time": "2025-11-05T14:53:25.000Z"}, {"author": "Brian Campbell", "text": "<p>it's there</p>", "time": "2025-11-05T14:53:29.000Z"}, {"author": "David Waite", "text": "<p><span aria-label=\"wave\" class=\"emoji emoji-1f44b\" role=\"img\" title=\"wave\">:wave:</span></p>", "time": "2025-11-05T14:53:44.000Z"}, {"author": "John Bradley", "text": "<p><span aria-label=\"wave\" class=\"emoji emoji-1f44b\" role=\"img\" title=\"wave\">:wave:</span></p>", "time": "2025-11-05T14:54:46.000Z"}, {"author": "David Waite", "text": "<p>slightly larger room next time</p>", "time": "2025-11-05T15:00:12.000Z"}, {"author": "John Bradley", "text": "<p>Now I know what it feels like to be replaced by AI</p>", "time": "2025-11-05T15:01:09.000Z"}, {"author": "Emil Lundberg", "text": "<p><a href=\"https://google.github.io/longfellow-zk/\">https://google.github.io/longfellow-zk/</a></p>", "time": "2025-11-05T15:02:55.000Z"}, {"author": "David Waite", "text": "<p>I believe they are trying to establish regulations around creating such AI :-)</p>", "time": "2025-11-05T15:03:10.000Z"}, {"author": "Leif Johansson", "text": "<p>Totally agree with Deb btw</p>", "time": "2025-11-05T15:12:48.000Z"}, {"author": "Leif Johansson", "text": "<p><a href=\"https://github.com/abetterinternet/zk-cred-longfellow\">https://github.com/abetterinternet/zk-cred-longfellow</a></p>", "time": "2025-11-05T15:14:13.000Z"}, {"author": "Leif Johansson", "text": "<p>ISRGs rust code</p>", "time": "2025-11-05T15:14:26.000Z"}, {"author": "David Waite", "text": "<p>apologies for going over time</p>", "time": "2025-11-05T15:21:23.000Z"}, {"author": "Karen O'Donoghue", "text": "<p>no worries. good discussion.</p>", "time": "2025-11-05T15:22:22.000Z"}, {"author": "Mike Ounsworth", "text": "<p>Hannes, for the minutes, could you please summarize your most recent point?</p>", "time": "2025-11-05T15:45:12.000Z"}, {"author": "Mike Ounsworth", "text": "<p>Personal opinion: doing this in front of the room is not proving to be productive. I suspect that a smaller more private discussion among the interested parties would be more productive.</p>", "time": "2025-11-05T15:46:56.000Z"}, {"author": "John Preu\u00df Mattsson", "text": "<p>A smaller meeting seems the way to go.</p>", "time": "2025-11-05T15:47:43.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>For the minutes I was trying to convey two items: 1) We are updating RFC 7516 semantics in the draft with the appropriate close (see first page - header). 2) We can change the semantics of the alg field.</p>", "time": "2025-11-05T15:48:11.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Please include the remote participants in the design team meeting.</p>", "time": "2025-11-05T15:49:08.000Z"}, {"author": "Filip Skokan", "text": "<p>yes please</p>", "time": "2025-11-05T15:49:30.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Exactly what Deb says. We can selectively update an RFC.</p>", "time": "2025-11-05T15:49:45.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>This is what we are doing</p>", "time": "2025-11-05T15:49:49.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Saying that we cannot do this, as Brian did in his slides is incorrectr</p>", "time": "2025-11-05T15:50:01.000Z"}, {"author": "Filip Skokan", "text": "<p>@hannes sorry, we clearly didn't understand Brian's slides the same way</p>", "time": "2025-11-05T15:50:53.000Z"}, {"author": "Filip Skokan", "text": "<p>a full on bis document was not the suggestion</p>", "time": "2025-11-05T15:51:18.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Brian also did not understand my remarks either. So, there is clearly a need to discuss this.</p>", "time": "2025-11-05T15:51:23.000Z"}, {"author": "Filip Skokan", "text": "<p>yeah, let's</p>", "time": "2025-11-05T15:51:33.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Mike explained why he has not been able to schedule a meeting. Would have been good to discuss this topic in a meeting.</p>", "time": "2025-11-05T15:52:53.000Z"}, {"author": "Deb Cooley", "text": "<p>The room is available (currently):  Wed afternoon before 1700, Thurs afternoon, Friday morning.  Bash away (somewhere else) and let me know - slack works.</p>", "time": "2025-11-05T15:55:01.000Z"}, {"author": "Karen O'Donoghue", "text": "<p>@Deb we'll gather after this during the break to nail a time and get back to you.</p>", "time": "2025-11-05T15:56:09.000Z"}, {"author": "Deb Cooley", "text": "<p>perfect</p>", "time": "2025-11-05T15:58:08.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>It would be good to nail down what changes need to be made. I would like to see examples.</p>", "time": "2025-11-05T15:58:12.000Z"}, {"author": "Deb Cooley", "text": "<p>None is being deprecated for everything?</p>", "time": "2025-11-05T16:02:06.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Was there a conclusion on Neil's presentation?</p>", "time": "2025-11-05T16:02:37.000Z"}, {"author": "Mike Ounsworth", "text": "<p><span class=\"user-mention silent\" data-user-id=\"331\">Deb Cooley</span> <a href=\"#narrow/channel/358-jose/topic/ietf-124/near/191670\">said</a>:</p>\n<blockquote>\n<p>None is being deprecated for everything?</p>\n</blockquote>\n<p>... it only exists as a signature algorithm, not as a keyex / enc, right?</p>", "time": "2025-11-05T16:02:45.000Z"}, {"author": "Neil Madden", "text": "<p>Yes - it\u2019s only a JWS algorithm, and is being deprecated for that</p>", "time": "2025-11-05T16:03:09.000Z"}, {"author": "Brian Campbell", "text": "<p><a href=\"https://mailarchive.ietf.org/arch/msg/jose/wBQR1eCcZ4rpqsPV2qJ8NCnT9Fk/\">https://mailarchive.ietf.org/arch/msg/jose/wBQR1eCcZ4rpqsPV2qJ8NCnT9Fk/</a> is the message</p>", "time": "2025-11-05T16:03:12.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Thanks!</p>", "time": "2025-11-05T16:03:31.000Z"}, {"author": "Karen O'Donoghue", "text": "<p>@Hannes conclusion: specific question on mailing list wrt examples in/out.... decide... update if necessary... then WGLC.</p>", "time": "2025-11-05T16:03:43.000Z"}, {"author": "Neil Madden", "text": "<p>Hannes - I think the action is with the chairs to discuss and send a message to the list to resolve.</p>", "time": "2025-11-05T16:03:50.000Z"}, {"author": "Karen O'Donoghue", "text": "<p>what Neil said...</p>", "time": "2025-11-05T16:04:11.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>I have no opinion regarding listing examples or not.</p>", "time": "2025-11-05T16:05:08.000Z"}, {"author": "Jonathan Hammell", "text": "<p>To Deb's point, COSE_Sign allows multiple signatures to be present. Doesn't force both to be used, but allows for the verifier to transition if there is a problem with one.</p>", "time": "2025-11-05T16:13:59.000Z"}, {"author": "John Preu\u00df Mattsson", "text": "<p>+1 to what Deb is saying.</p>\n<p>And if we should do composites anywhere in IETF lets not do these composites that are garantueed to decrease the security properties of ML-DSA</p>", "time": "2025-11-05T16:14:06.000Z"}, {"author": "Neil Madden", "text": "<p>Is the FIDO metadata service still a big signed JWT? That seems like a potential use-case.</p>", "time": "2025-11-05T16:14:34.000Z"}, {"author": "Emil Lundberg", "text": "<p>it is</p>", "time": "2025-11-05T16:14:43.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>Mostly agree with Deb here, EXCEPT that JOSE is a toolkit other people use to build stuff with.</p>", "time": "2025-11-05T16:14:48.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>So the point really applies to people who would use it.</p>", "time": "2025-11-05T16:15:12.000Z"}, {"author": "John Bradley", "text": "<p>It is more complicated.  From a HSM TPM secure element point of view it is more work and more side channel protection annalisys for each alg</p>", "time": "2025-11-05T16:18:59.000Z"}, {"author": "Michael P", "text": "<p>Agree with Deb and others in this chat. Also one of the motivates stated in the slides was to align with other parts of IETF but TLS, for example, have not decided how to do hybrid authentication</p>", "time": "2025-11-05T16:19:24.000Z"}, {"author": "Jonathan Hammell", "text": "<p>Suggesting to limit the number of hybrid combinations is something that was long debated and largely not achieved within LAMPS.  John mentioned BSI recommendations as applying to EU digital credentials.  That may require combinations not currently listed, resulting in more options.</p>", "time": "2025-11-05T16:19:32.000Z"}, {"author": "John Bradley", "text": "<p>Gotta love Brainpool:)</p>", "time": "2025-11-05T16:20:13.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Stefan, how is the mechanism supposed to work? You are using ECDH to generate a symmetric key. Then, you use that symmetric key as the key for an HMAC?</p>", "time": "2025-11-05T16:20:47.000Z"}, {"author": "John Preu\u00df Mattsson", "text": "<p>TLS WG has to my knowledge decided that hybrid authentication will be disucssed \"much later\"</p>", "time": "2025-11-05T16:21:00.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>How is authentication done using this scheme?</p>", "time": "2025-11-05T16:21:55.000Z"}, {"author": "Neil Madden", "text": "<p>It\u2019s static-static ECDH, I believe so there\u2019s implicit authentication.</p>", "time": "2025-11-05T16:22:32.000Z"}, {"author": "Emil Lundberg", "text": "<p>\"Derive basic config from name?\" - my impression has been things are moving away from parsable alg identifiers, in favour of instead looking up fully-specified algs (a la RFC 9864) in a registry, to prevent malicious or accidental bad combinations of algorithms</p>", "time": "2025-11-05T16:23:42.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>We just ripped out the MAC variant of the COSE HPKE specification because the security properties where not there.</p>", "time": "2025-11-05T16:26:06.000Z"}, {"author": "Mike Ounsworth", "text": "<p>For the minutes, I am summarizing Hannes' comment this way. Is that a correct summarization?<br>\n(I also injected some of my personal opinion, since I agree with this comment)</p>\n<blockquote>\n<p>but in the case where there are ephemeral keys, then you don't necessarily get authentication, or you don't get it with the security properties that you expect. So you have to be very careful.</p>\n</blockquote>", "time": "2025-11-05T16:27:06.000Z"}, {"author": "Kris Kwiatkowski", "text": "<p><span class=\"user-mention silent\" data-user-id=\"693\">Jonathan Hammell</span> <a href=\"#narrow/channel/358-jose/topic/ietf-124/near/191818\">said</a>:</p>\n<blockquote>\n<p>Suggesting to limit the number of hybrid combinations is something that was long debated and largely not achieved within LAMPS.  John mentioned BSI recommendations as applying to EU digital credentials.  That may require combinations not currently listed, resulting in more options.</p>\n</blockquote>\n<p>So then maybe what we really need is MLDSA87-BrainpoolP384r1 and that's really all what's needed.</p>", "time": "2025-11-05T16:27:38.000Z"}, {"author": "John Bradley", "text": "<p>The MAC stuff comes from a desire by some counries to have repudiable assertions.   Normally the reverse of what you want for securty.   It is privacy driving this.</p>", "time": "2025-11-05T16:27:54.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Are you going to send Tiru, Filip and myself an email regarding the timeslot for the design team meeting? It is possible that the meeting will be stopped any minute</p>", "time": "2025-11-05T16:32:38.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Thanks!</p>", "time": "2025-11-05T16:32:56.000Z"}]