[Bug 25607] Need to advise authors about security considerations

https://www.w3.org/Bugs/Public/show_bug.cgi?id=25607

--- Comment #19 from Mark Nottingham <mnot@mnot.net> ---
(In reply to Ryan Sleevi from comment #17)
> I strongly object/oppose this. You are the only person in this WG advocating
> MD2/MD5. You're proposed inclusion is seemingly an attempt to circumvent any
> WG discussion of these, by trying to include a normative note that precludes
> their use.

Rather than trying to ascribe motives here, I think everyone would benefit from
this issue actually being discussed in the WG, full stop.

According to its home page, this WG hasn't had a meeting since 03 March
(although I see unreferenced minutes in the archive from 05 May). There has
been very little discussion of this issue on the mailing list beyond a
back-and-forth between Ryan and Rich, despite the WG listing 70 participants in
Good Standing. 

In fact, the only other WG discussion I can find on this issue (beyond Harry
and Virginie's much-appreciated attempts to mediate an outcome) is Richard
Barnes' comment:
  http://lists.w3.org/Archives/Public/public-webcrypto/2014May/0037.html
... which seems to support an addition along the lines that Rich proposed.

Did I miss something?

-- 
You are receiving this mail because:
You are on the CC list for the bug.

Received on Tuesday, 1 July 2014 01:37:11 UTC