Sent-To: 
On Wed, Apr 02, 2014 at 08:18:07AM -0700, Watson Ladd wrote:
> On Wed, Apr 2, 2014 at 7:57 AM, Donald Eastlake <[email protected]> wrote:
> > Hi,
> >
> > Yes, the "bad ideas" section of RFC 4086bis
> > (draft-eastlake-randomness3-00) seems like a good place to collect
> > additional things not to do.
> >
> 
> No. Do not enumerate badness.

Actually the PERL documentation claims that there are psychological
studies that show that prohibitions stick better than instruction on
correct behavior.

> Instead model correct behavior.

The problem with this approach is that we do not know what those are,
only what has been broken.  Our new designs will change based on what
we learn, but what has been broken will not.

Whether such instruction is appropriate for RFC or not is a valid
question.

> You will
> not be able to list all the ways someone can make a mistake, but you
> can explain a way to do things right.

For current assumptions, yes.
-- 
http://www.subspacefield.org/~travis/
Remediating... LIKE A BOSS


Attachment: pgp_mb3EugI_M.pgp
Description: PGP signature

_______________________________________________
dsfjdssdfsd mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dsfjdssdfsd

Reply via email to