IETF/IRTF: ZK adoption, attestation bugs, PQ signatures
CFRG opened an adoption call for a zero-knowledge draft while researchers disclosed critical attestation flaws tied to an IETF seat draft. TLS confirmed hybrid signature consensus direction, and TEAS, mail, OAuth, RADIUS, and emailcore lists carried feasibility disputes and last-call debates.
CFRG adoption call for Longfellow ZK
The CFRG opened a two-week call for adoption of draft-google-cfrg-libzk-03 (Longfellow ZK). Multiple implementers voiced support on the list. The outcome will shape IRTF zero-knowledge proof work that protocol designers and library authors track.
Critical attested-TLS vulnerabilities reported
Researchers disclosed three critical-severity vulnerabilities (CVSS 9.0 or higher) under the name EarlyAttestationBleed in two attested-TLS implementations used for confidential computing. The findings are tied to draft-fossati-seat-early-attestation. Operators and implementers of attested TLS need to assess exposure in early-attestation flows.
TLS list consensus on PQ+T hybrid signatures
The TLS working group is running a list consensus call to adopt post-quantum plus traditional hybrid signature work after polls at IETF 126. The call confirms working-group direction on hybrid signatures. TLS stack maintainers and deployers should watch the resulting charter or draft changes.
Feasibility dispute on power-aware TE
Aijun Wang argued that distributed power-aware traffic engineering is impossible in the context of the draft-many-teas-power-steering adoption call. Authors defended metric-modified CSPF and power groups. The heated TEAS exchange affects energy-aware TE standards under consideration.
Distinguishing e2ee from encryption-on-arrival
The mailmaint working group discussed the need for a standard that lets mail user agents distinguish sender end-to-end encryption from provider encryption-on-arrival or at-rest encryption. Participants framed the gap as a practical MUA and user-clarity problem. Mail client and service implementers have a stake in any resulting specification.
OAuth call for fine-grained authorization interest
The OAuth working group issued a call for interest in fine-grained authorization, including use by AI agents, as an IETF 126 follow-up. Discussion referenced existing drafts on missions and RAR remediation. The response will influence whether the WG takes on richer authorization models.
RADIUS/(D)TLS-bis connection close debate
The radext working group debated, during final updates to RADIUS/(D)TLS-bis, whether rejected RadSec connections must close immediately or may use tarpitting against misbehaving clients. The exchange was heated and centered on defensive behavior. RADIUS over TLS operators and implementers should note the eventual MUST/MAY language.
Emailcore last-call on cleartext SMTP
In last-call discussion of the emailcore applicability statement, participants debated whether the draft must retain mandatory cleartext SMTP support alongside TLS, citing mail statistics. The thread remains technical and unresolved in the provided traffic. Email core implementers and operators are directly affected by the final applicability requirements.