[{"author": "Hannes Tschofenig", "text": "<p><a href=\"https://notes.ietf.org/notes-ietf-interim-2023-scitt-23-scitt\">https://notes.ietf.org/notes-ietf-interim-2023-scitt-23-scitt</a></p>", "time": "2023-07-03T15:10:02Z"}, {"author": "Hannes Tschofenig", "text": "<p><a href=\"https://www.ietf.org/archive/id/draft-ietf-scitt-architecture-01.html\">https://www.ietf.org/archive/id/draft-ietf-scitt-architecture-01.html</a></p>", "time": "2023-07-03T15:11:56Z"}, {"author": "Dick Brooks", "text": "<p>I agree with Roy - trust in the TS is sufficient to trust the data provided</p>", "time": "2023-07-03T15:26:59Z"}, {"author": "Orie Steele", "text": "<p>\"registration policy\" remains confusing, when compared to \"issuer enrollment\"</p>", "time": "2023-07-03T15:27:41Z"}, {"author": "Orie Steele", "text": "<p>registration policy applies to adding signed statements</p>", "time": "2023-07-03T15:27:56Z"}, {"author": "Orie Steele", "text": "<p>knowing who you trust to sign statements applies to \"issuer enrollment\".</p>", "time": "2023-07-03T15:28:14Z"}, {"author": "Hannes Tschofenig", "text": "<p>If you have a better term, Orie, happy to take it</p>", "time": "2023-07-03T15:32:56Z"}, {"author": "Orie Steele", "text": "<p>there is also this PR, which I welcome any feedback on: <a href=\"https://github.com/ietf-scitt/draft-steele-cose-merkle-tree-proofs/pull/18\">https://github.com/ietf-scitt/draft-steele-cose-merkle-tree-proofs/pull/18</a></p>", "time": "2023-07-03T15:36:49Z"}, {"author": "Hannes Tschofenig", "text": "<p><a href=\"https://github.com/ietf-wg-scitt/draft-ietf-scitt-architecture\">https://github.com/ietf-wg-scitt/draft-ietf-scitt-architecture</a></p>", "time": "2023-07-03T15:37:14Z"}, {"author": "Mitja Goroshevsky", "text": "<p><a href=\"https://ietf-wg-scitt.github.io/draft-ietf-scitt-architecture/draft-ietf-scitt-architecture.html\">https://ietf-wg-scitt.github.io/draft-ietf-scitt-architecture/draft-ietf-scitt-architecture.html</a></p>", "time": "2023-07-03T15:39:20Z"}, {"author": "Orie Steele", "text": "<p>might be better to describe feed as being the \"transparency services accepted name\"... issuer proposes it, but transparency service registration policy determins if it will be accepted.</p>", "time": "2023-07-03T15:43:07Z"}, {"author": "Orie Steele", "text": "<p>feed is an \"identifier\" for a \"topic\"... could be about anything, since identifier can refer to anything.</p>", "time": "2023-07-03T15:44:19Z"}, {"author": "Henk Birkholz", "text": "<p>a \"registration policy\" feed?</p>", "time": "2023-07-03T15:51:07Z"}, {"author": "Orie Steele", "text": "<p>you might consider asking the TS for transparency regarding its issuers</p>", "time": "2023-07-03T15:52:19Z"}, {"author": "Orie Steele", "text": "<p>but that is different than asking for transparency regarding artifacts</p>", "time": "2023-07-03T15:52:39Z"}, {"author": "Orie Steele", "text": "<p>sounds like this question is actually about key transparency</p>", "time": "2023-07-03T15:52:58Z"}, {"author": "Orie Steele", "text": "<p>the consumer is trusting the TS... thats the whole point.</p>", "time": "2023-07-03T15:53:36Z"}, {"author": "Orie Steele", "text": "<p>the consumer does not trust \"author signatures\"</p>", "time": "2023-07-03T15:53:50Z"}, {"author": "Orie Steele", "text": "<p>the consumer trusts \"package management signatures\"</p>", "time": "2023-07-03T15:54:01Z"}, {"author": "Cedric Fournet", "text": "<p>Let's discuss it as a separate issue. (We considered a few solutions, but none of them may fully solve this issue.)</p>", "time": "2023-07-03T15:54:02Z"}, {"author": "Raymond Lutz", "text": "<p>I think it will help if we have some specific usage examples of the service in gory detail.</p>", "time": "2023-07-03T15:54:34Z"}, {"author": "Cedric Fournet", "text": "<p>And yes, a registration policy feed + a way to refer to the last registered statement on that feed is one of these solutions.</p>", "time": "2023-07-03T15:54:48Z"}, {"author": "Orie Steele", "text": "<p>You used to trust Apple app store, but then they started letting anyone publish apps... how did you learn they lowered there standards? What can you do as a consumer of apps?</p>", "time": "2023-07-03T15:55:46Z"}, {"author": "Orie Steele", "text": "<p>etc...</p>", "time": "2023-07-03T15:55:49Z"}, {"author": "Orie Steele", "text": "<p>im, you are really asking for an endorsement on a TS</p>", "time": "2023-07-03T15:56:09Z"}, {"author": "Orie Steele", "text": "<p>an answer to \"which TS should I trust for statements about xyz artifacts\"</p>", "time": "2023-07-03T15:56:35Z"}, {"author": "Orie Steele", "text": "<p>first part TS (where the issuer and the TS are the same) is less trustworthy, because incentives are not aligned</p>", "time": "2023-07-03T15:57:08Z"}, {"author": "Mitja Goroshevsky", "text": "<p>You should trust no one actually.</p>", "time": "2023-07-03T15:57:24Z"}, {"author": "Orie Steele", "text": "<p>^ true story : )</p>", "time": "2023-07-03T15:57:48Z"}, {"author": "Orie Steele", "text": "<p>+1 Hannes! VRFs def interesting</p>", "time": "2023-07-03T15:58:26Z"}, {"author": "Raymond Lutz", "text": "<p>It seems that the TS mainly provides a way to assess blame if something goes wrong. If users know they can be blamed, then they start to be more honest. We hope.</p>", "time": "2023-07-03T15:58:29Z"}, {"author": "Orie Steele", "text": "<p>yes, consensus call is for the charter.</p>", "time": "2023-07-03T16:00:23Z"}, {"author": "Hannes Tschofenig", "text": "<p><a href=\"https://bren2010.github.io/draft-key-transparency/draft-mcmillion-key-transparency.html\">https://bren2010.github.io/draft-key-transparency/draft-mcmillion-key-transparency.html</a></p>", "time": "2023-07-03T16:00:31Z"}, {"author": "Raymond Lutz", "text": "<p>Not sure if we can avoid sometimes parallel structures even if we try to avoid them. I see no reason to duplicate KT structures.</p>", "time": "2023-07-03T16:01:07Z"}, {"author": "Orie Steele", "text": "<p>they need \"search proofs\" and \"proofs of non inclusion\"</p>", "time": "2023-07-03T16:01:43Z"}, {"author": "Raymond Lutz", "text": "<p>registries might have different structures btween SCITT and KT.</p>", "time": "2023-07-03T16:02:31Z"}]