core-wg / echo-request-tag

Other
0 stars 0 forks source link

Spectrum of Echo uses #75

Closed chrysn closed 3 years ago

chrysn commented 3 years ago

Closes: https://github.com/core-wg/echo-request-tag/issues/74


While the first commit is close to the text I'd pick here (and ready to be vetted), some points are still open:

[edit: and yeah, I didn't run this through a final reading yet after forming the underlying ideas as I was writing, so there may be some unclosed parens or odd sentences left; sorry for those, hope the sentiment is clear still].

chrysn commented 3 years ago

Updated now to align further parts of the document, requesting preliminary review.

An open discussion point is that by the careful wording around source-of-truth, for the short Echo values we're not really claiming "freshness" (kind of leaving the term "freshness" for where the server can provably-even-with-a-malicious-client know that it is newer-than). I think it's generally fine to use the strong sense of freshness, but that means that we illustrate in echo-figure-event does not deserve the term "freshness". Options are:

Suggestions? I'm undecided between them, and would prefer not to toss a coin.

chrysn commented 3 years ago

(Ticking off the "protected Echo" box now because the security considerations line "Echo values without the protection of randomness or a MAC" reads reasonably well; if there's clarification needed left we can find that during review).

chrysn commented 3 years ago

Ping @gselander and @emanjon; I could really need a bit of feedback there.

chrysn commented 3 years ago

I'm merging this now to allow taking the final editing steps, but still would like to have another pair of eyes here -- but worst case that can happen after a submission tomorrow at cut-off date, and if the need for changes does come up, we work that into the P2P responses and let the reviewers know that a follow-up will come when the cut-off is over.