[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [openpgp] Proposal to include AEAD OCB mode to 4880bis

On Wed, Nov 01, 2017 at 10:35:59AM -0400, Derek Atkins wrote:
> "brian m. carlson" <sandals@xxxxxxxxxxxxxxxxxxxx> writes:
> > Yes, I would much prefer that we let OCB happen in a separate draft.
> > Then all the patent problems occur in a separate specification that
> > doesn't affect the core OpenPGP.
> I don't think you understand the relationship between the specification
> and IP.  Specifically, whether OCB is in the main spec or a secondard
> spec does not affect any IP/patent "problems".  Put another way,
> IP/patent "problems" occur for anyone who wants to implement OCB,
> regardless of where it is specified.  However having it in the main
> draft makes it easier to implement and audit, as Werner suggested.  The
> more places you have to reference, the more likely you'll make a
> mistake.

No, I completely understand it.  I strongly feel that OCB doesn't belong
in the main draft so we have a simple, complete, unencumbered spec.
Then it's very easy to avoid all the uncertainty (and there is a lot) on
OCB by simply not implementing the additional spec.  People can
implement the entire main RFC without having to even think about
patents, and that's valuable.

Otherwise, people have to end up explaining that yes, we implement the
spec, but no, we don't implement the patented parts, and that the spec
is implementable without the patented parts, and so on and so forth.  I
anticipate that this is a conversation that numerous people, not just
me, are going to have with company lawyers.

I strongly believe that our spec should be unencumbered.  I am still
strongly opposed to OCB because it's patented, but if it lives in a
separate spec, it's easy enough to just say, "Don't implement that RFC."
brian m. carlson / brian with sandals: Houston, Texas, US
https://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: https://keybase.io/bk2204

Attachment: signature.asc
Description: PGP signature

openpgp mailing list