Re: IETF privacy policy - update

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




--On Monday, July 05, 2010 11:40 AM -0700 Dave CROCKER
<dhc2@xxxxxxxxxxxx> wrote:

> Marshall,
> 
> On 7/5/2010 11:28 AM, Marshall Eubanks wrote:
>> I assume (for I do not know) that people are worried about
>> time involved in bringing a new RFC to publication.
> 
> The IESG often states that it is not difficult to bring an RFC
> to publication.
> 
> In any event, what makes this document more urgent, and in
> need of less scrutiny and processing, that any other potential
> RFC?
> 
> Personally, I would expect a document that attends to
> explicitly and complexly legal concerns to need /more/
> scrutiny than an entry-level technical specification, not less.

Agreed.

>> I don't see why this couldn't be divided in the way that the
>> Trust Legal Provisions have been :
>> 
>> - a RFC to set the _goals_ and basic framework of the privacy
>> policy, which might change something like every 5 years (or
>> less often if we are lucky) and
> 
> You expect the privacy policy, itself, to change more
> frequently than this?

I would hope not (either), but experience indicates that we have
even more trouble getting legal documents right than we do
protocol documents.  Having a lightweight and speedy mechanism
for correcting an incorrect realization of a policy outline laid
out by the IETF seems reasonable.  While I agree with you (Dave)
that getting the policy principles in place should not be so
urgent as to justify being done in haste, our experience
(especially in the IPR area, which is likely to involve the same
lawyers, both professional and amateur) has been that,
sometimes, making a correction to specific mechanisms already
deployed may be urgent.

> Also, the implication of your suggestion is that we would have
> a goals and framework document /after/ we have actual
> policies. This seems a bit, ummmm, backward.  It would make
> more sense to have the two in one document, absent some
> expectation of one being more stable than the other.

I did not read that into Marshall's note but assumed that we
would lay out the policy principles (the "goals and framework
document") in the IETF first and then proceed to instruct the
IASA to generate a specific policy statement for community
review.     "Policies first" would seem backwards to me too...
to put it mildly.

    john




_______________________________________________
Ietf mailing list
Ietf@xxxxxxxx
https://www.ietf.org/mailman/listinfo/ietf


[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Fedora Users]