Tuesday, November 8, 2022< ^ >
[12:47:22] <dkg> hello everyone!
[12:50:09] <zulipbot> (Stavros Kousidis) hi
[12:54:04] <vanitasvitae> \o/
[12:55:43] <dkg> we'll probably start in about 5 minutes
[12:55:50] <sftcd> in exactly 5:-)
[12:56:47] <zulipbot> (Robin Wilton) Hi everyone - so sorry I'm not able to join you in person :^(
[12:57:51] <dkg> there are many conflicts, as usual.  thanks for saying hi, Robin!
[12:58:18] <zulipbot> (Robin Wilton) I'm pleased and reassured to see so many masks! I'm afraid my experience elsewhere in the UK has been very different.
[12:59:40] <dkg> i wanted to be there in person, but other parts of life got in the way -- and had i gone through with being there in person, i would have failed to show up anyway, as i'm living in a household with an active COVID case ☹
[13:00:10] <sftcd> bummer, hope all recovered soon
[13:05:57] <zulipbot> (Robin Wilton) I admit I am not...
[13:06:53] <zulipbot> (Robin Wilton) For the notes: I am willing to do a (non expert!) review.
[13:07:24] <zulipbot> (Jonathan Hammell) I plan to review in the next couple weeks (as indicated in the room).
[13:07:37] <zulipbot> (Robin Wilton) (it's only 164 pages, after all...  ;^O  )
[13:08:19] <zulipbot> (Robin Wilton) If *everyone's* stepping off the cliff, it must be a good idea.
[13:08:27] <sftcd> thanks all for volunteering
[13:08:48] <sftcd> @robin: it's a wylie coyote kinda cliff so it'll be fine:-)
[13:11:05] <sftcd> for remote folks, feel free to jump into the queue (same for onsite folks)
[13:11:44] <zulipbot> (Robin Wilton) Just for clarity, I see two "draft-koch-openpgp-" documents, so make sure you're looking at the "rfc4880bis-00" draft, not the "webkey-service" draft.
[13:11:59] <sftcd> yes, as per recent list discussion
[13:12:01] <zulipbot> (Daniel Gillmor) that's right, it's rfc4880bis-00
[13:18:22] <zulipbot> (Daniel Gillmor) proposal: move version number from v5 to v6 for: Key, Signature, OPS, and PKESK
[13:19:32] <zulipbot> (Robin Wilton) I'm not qualified to make a decision at this point, sorry.
[13:24:47] <zulipbot> (Samuel Gwinn) Is it possible to remove one's vote
[13:26:01] <zulipbot> (Samuel Gwinn) I do not feel qualified to weigh in. I did not note the option to abstain before I clicked an option.
[13:27:17] <sftcd> @samuel, no problem we're score it at 12:0 so
[13:34:22] <sftcd> aron's proposal: pick salt length based on hash alg used in signature
[13:35:37] <zulipbot> (Robin Wilton) @sftcd Your text here is how I understood it too.
[13:35:45] <sftcd> ta
[13:37:29] <sftcd> dkg variant: add salt length to IANA registry for sig algs
[13:37:31] <zulipbot> (Robin Wilton) Is the goal of Aron's proposal to prevent people from using a stronger hashing algorithm with a weaker (shorter) salt?
[13:39:17] <sftcd> Robin Wilton_web_187: did you want me to ask that in the room or join the queue?
[13:40:09] <zulipbot> (Robin Wilton) @sftcd Since you and Aron are both in the room, would you mind asking (mic line permitting).
[13:40:17] <sftcd> will do
[13:41:32] <zulipbot> (Jonathan Hammell) Maybe PQ will result in v7 sigs. 😉
[13:42:28] <sftcd> @robin: he's answering you now anyway:-)
[13:43:56] <zulipbot> (Robin Wilton) ack
[13:46:36] <zulipbot> (Robin Wilton) LOL
[13:47:02] <zulipbot> (Robin Wilton) OK, I'll get back in my box ;^)
[13:47:32] <zulipbot> (Ira McDonald) polls are BINARY only
[13:53:23] <zulipbot> (Robin Wilton) Am I reading this correctly... that <4GB is considered to be a "small" message? 😳
[13:54:11] <zulipbot> (Robin Wilton) Ah, OK, thanks.
[13:56:28] <zulipbot> (Jonathan Hammell) proposed trailer fix would be another deviation from draft-koch, right?
[13:56:45] <dkg> yes, it is another deviation from draft-koch
[13:57:15] <sftcd> but we'll be v6 signatures then right, so we avoid the non-interop (or don't make it worse)
[14:00:32] <zulipbot> (Robert Lee) Assuming old versions will go away because we've asked them to feels very optimistic to me.  Is there a reason to be confident that v3 is actually going to go away?
[14:08:48] <zulipbot> (Robin Wilton) @sftcd No objection
[14:09:37] <sftcd> ta
[14:09:40] <zulipbot> (Robin Wilton) I think we've already discussed enough work items to keep people busy until re-chartering becomes the next logical step.
[14:18:48] <zulipbot> (Mike Ounsworth) Ok, dumb question: what's "SPECIFICATION REQUIRED" ?
[14:19:01] <zulipbot> (Daniel Gillmor) that's what we're talking about here
[14:19:14] <zulipbot> (Mike Ounsworth) Yeah, I see that, but I don't know what the words mean
[14:19:53] <zulipbot> (Daniel Gillmor) we're trying to figure out how to tell the designated expert what we think is a sufficient "specification"
[14:22:42] <zulipbot> (Roman Danyliw) For registration policy possibilities, see Section 4 of
[14:23:45] <zulipbot> (Roman Danyliw) "Specification Required" is Section 4.6 =
[14:27:11] <zulipbot> (Mike Ounsworth) @**Aron Wussler** when you say "composite", do you mean the key / sig / kem wire encoding according to draft-ounsworth-pq-composite-keys-03, or something else?
If you like, I would love to sit down with you and talk about terminology as per draft-driscoll-pqt-hybrid-terminology to avoid confusion.
[14:28:38] <sftcd> I'm gonna suggest we have an interim meeting *after* the end of WGLC and when we've hit the "publication requested" button for crypto-refresh - sound ok?
[14:28:58] <sftcd> with rechartering being the topic of that interim
[14:29:18] <dkg> sftcd: sounds reasonable
[14:31:34] <zulipbot> (Mike Ounsworth) Algorithm pairs look reasonable to me at first glance. The only comment is whether you actually need that many?
[14:31:47] <dkg> i'm also scared of the number of options
[14:31:48] <sftcd> thanks all
[14:31:52] <dkg> i recommend just choosing two
[14:32:09] <zulipbot> (Robin Wilton) Thanks everyone
[14:32:15] <dkg> if folks find they need more, they can specify them later
