TL;DR – Hybrid Public Key Encryption
franziskuskiefer.de
franziskuskiefer.de
The fact that it's being RFCed?
Traditionally you generate a random session key and then encrypt it using the public key of the recipient. The public/secret keypair is generated standalone where you optionally encrypt the secret bit of the keypair separately with a passphrase.
Not yet sure how this scheme would work in practice and what the advantage is...
Cloudflare's post [0] has some more background information.
[0] https://blog.cloudflare.com/hybrid-public-key-encryption/
(never mind the hostile climate today, headduck)
If so, it would be good in both TFA and the RFC to state this up front. Otherwise, one might wonder if it ain’t broke, why are we fixing it?
If not, all corrections/explications hatefully received!
Protocols like this skip some of these very important and useful features.
Another major benefit of HPKE is a shared key schedule. Two parties can generate as many symmetric keys as they would like over a persistent conversation. This kind of provides ‘sub keys’, but within the context of a conversation, as they are not long lived.
GPG’s web of trust model is powerful but is limited in contexts where you have no prior trust. The world’s existing PKI structure, with a handful of root CAs, is already well established and trusted by nearly every device on the planet.
With the WOT you can choose who you trust. In particular you have the choice not to trust every single one of the several thousand second level CAs that currently exist.
None of this explains what HPKE is and why anyone would be interested in it.
In essence: you're correct about that part.