#IETF

2025-06-14

@battlemesh @vortex @cypherhippie and another, non-tangible thing that's kept artifically scarce, but which is still important to community networks imo: Access to standardization, like at the #IEEE. The #IETF for the internet is awesome and exemplary in their organization and openess. But to propose and vote for changes to the #WLAN or #WiFi standards you need to be a member of the IEEE or WiFi alliance. So you basically have to buy your voting power their for a lot of money.

2025-06-14

The IETF working group that I co-chair, PQUIP, had its first RFC published today. RFC 9794, "Terminology for Post-Quantum Traditional Hybrid Schemes", lists and describes terms used in post-quantum cryptography that are specific to the hybrid schemes that have become the focus for much of the PQC development work.

In short hybrid schemes are those that fully mix both post-quantum and traditional asymmetric algorithms. There are a lot of ways to mix them (some better than others), and thus there are a lot of properties that different mixtures have. The result is a lot of potentially confusing vocabulary full of similar-looking four-word chains. This document lays out all the differences so that other groups (other IETF working groups, other standards development organizations, governments making standards, ...) can be precise about what schemes they are adopting and why.

Congrats to the WG and the RFC authors!

datatracker.ietf.org/doc/rfc97

#ietf #rfc #pqc
(not using hashtag-hybrid because this ain't about cars, and certainly not using hashtag-crypto because bleaugh)

2025-06-11

At a security conference, someone referenced an obsolete RFC... what fun it was to show them an official "IETF Protocol Police" badge. (OK, it's the AD's... but still... fun to whip out).

#ietf #standards #security #police

Photo of a badge that looks like an official US police badge labled as "IETF Protocol Police"
Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2025-05-30

L'#IETF vient de créer un groupe de travail nommé PROCON mais qui n'est pas destiné à soutenir les crétins. datatracker.ietf.org/group/pro

Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2025-05-28

Sandoche Balakrichenan explique les concepts d'identité sur l'Internet (adresse IP, nom de domaine, etc) et sa normalisation (et le multipartieprenantisme bortzmeyer.org/multipartiepren).

#NetGouv #IETF

2025-05-27

heise+ | Gemeinnütziges Web: Nonprofit-Organisationen als Gestalter der digitalen Welt

Wir geben einen Überblick über gemeinnützige Institutionen, die maßgeblich an der Entwicklung und inhaltlichen Gestaltung des Webs beteiligt sind.

heise.de/hintergrund/Gemeinnue

#ApacheSoftwareFoundation #FreeSoftwareFoundation #IANA #ICANN #IETF #Internet #IT #LinuxFoundation #Mozilla #WC #Wikimedia #news

Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2025-05-23

#CENTR Now, #RPP,, the [mostly for domain names] provisioning protocol which wants to replace #EPP.

An #IETF working group is designing it. The goal: REST architecture, and stuff that even a Javascript developer know (HTTPS and JSON).

Guillaume-Jean Herbietgjherbiet@mamot.fr
2025-05-20

@paulehoffman @jpmens @winfried CLI access to #ietf #rfc: you made my day!

2025-05-19

New blog article on "Post-quantum cryptography in #OpenPGP":

openpgp.foo/posts/2025-05-pqc/

#PQC #IETF

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-14

IETF organized a "PQC Dialogue with
Government Stakeholders" meeting. This post by John Preuß Mattsson is very informative:

groups.google.com/a/list.nist.

Abstract:
- EU: Transition for ”Harvest now, decrypt later” should be done by the end of 2030 and in general, the whole transition by the end of 2035. Not legally binding but might become law in the future.
- US, CA, UK, all agree on a timeline targeting around 2035 for mass adoption of quantum-resistant requirements.
- Heated discussion on the topic of "pure" vs "hybrid" schemes. BSI recommend hybrids for everything except for hash-based signatures.
- Very strong agreement that PQC is the priority. BSI says QKD is not mature and even long-term the only possible use case would be defense-in-depth in niche application. UK NCSC and NIST does not endorse QKD. Sweden says that QKD will never be useful.
- Discussion about paywalled standards. EU and US courts have decided that access to standards referenced by law is a human right.

#pqc #quantum #cryptography #nist #bsi #eu #ietf #nsa

Guillaume-Jean Herbietgjherbiet@mamot.fr
2025-05-13

Question #francophonie du jour pour ceux qui suivent (de près ou de loin) les travaux de l’#IETF. Quand il s’agit de se référer à un document de type #RFC, vous dites :

Cc. @ietf @bortzmeyer

Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2025-05-07

"QUIC, or the battle that never was: A case of infrastructuring control over Internet traffic"

Standardization of an Internet protocol by the #IETF, seen from social sciences.

#QUIC

journals.sagepub.com/doi/10.11

Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2025-05-05

Les protocoles Internet plutôt applicatifs transportent souvent du texte qui sera montré aux utilisateurices (HTTP est l'exemple typique).
Les protocoles Internet plutôt d'infrastructure (BGP, DNS, NTP) ne transportent typiquement jamais de texte destiné aux utilisateurices. (Je vous laisse chercher une ou deux exceptions.)
Faut-il changer cela ? (Grosse discussion à l'#IETF.)

Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2025-05-05

#IETF
In Internet-Draft draft-ietf-dnsop-structured-dns-error-15, I am mentioned twice in the acknowledgments.
This is because I noticed two missing commas and reported them.

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-04

@jens I think it's really sad for an organization like #IETF to still cling to in-person meetings.

  • I'd be more understanding it they were like EuroNCAP or OSHA, NTSB or other orgs that have to deal with physical safety and may include testing as part of their meetings with certified professionals assessing everything to quickly allow decisions.

I mean none of the folks at IETF's meetings are "#TechIlliterates" and it's not as if group videocalling and screensharing is something absurdly expensive nor that these meetings require actual privacy as per sensitivity of their nature.

  • Aslo with the current regime in place the USA is a "can't enter" for more people than ever before, as neither ESTA nor a Visa guarantees one is being let in.
2025-05-01

Internet Standards Almanac: Who’s really shaping the internet? Our new tool helps answers three key questions:

- Who leads? Which actors dominate formal leadership positions, including chairing various working groups and committees.

- Who speaks? Which actors dominate discussions and mailing lists.

- Who publishes? Which actors author the largest number of technical standards.

article19.org/resources/intern

#InternetStandards #SDO #IETF #IRTF #W3C

A cute cat in front of a graph
Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2025-04-29

Tadaaaam ! L'#IETF revient en Chine. ietf.org/meeting/125/ Je n'ai jamais visité Shenzhen.

Jeffrey Haasjhaas@a2mi.social
2025-04-23

The IETF community survey gives a nice sense about how the organization is running, and how participation has been going.

ietf.org/media/documents/IETF_

#ietf

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst