[Cryptography] NSA voting on TLS encryption at the IETF TLS WG

Theodore Tso tytso at mit.edu
Sun Jul 12 19:47:23 EDT 2026


On Wed, Jul 08, 2026 at 11:55:22PM -0500, Peter Fairbrother wrote:
> On 08/07/2026 20:46, Salz, Rich via cryptography wrote:
> 
> > The job of the IETF if not to pick the best and only the best.

>From context, I think what Rich was meaning to say was "The job of the
IETF _is_ not to pick the best and only the best".

The rest of what Rich's satement, which gives that context was:

   And best, particularly for security, often implies trade-offs such
   as message size, deployment difficult, overall operating
   environment, and so on.

> Surely, it is exactly that? Or at least to encourage that?

There really is no such thing as "best".  Certainly not a single
"best".

So if you look at protocol standardized by the IETf, there will be
specifications for a huge number of different options, and some may be
marked "informational", and some may be marked "recommended", and some
may even be marked "obsolete" at the time when the RFC was published.
(This tends to happen if the standard was in wide use for a long-time
before getting adopted by the IETF, and so there might be some legacy
options that you might want to document --- for example, if you need
to backwards compatibility with ancient Windows 95 or OS/2 machines
still in active use --- such as in use by the US Air Traffic Control,
for example.  Hopefully that will give you a nice, warm, fuzzy feeling
the next time you get on board an aircraft.  :-)

This is why, for example, there are RFC's documenting the use of
Russian GOST cyper suites.  They are not recommended by the IETF, but
there might be some situations where they might make sense.

Cheers,

						- Ted


More information about the cryptography mailing list