I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. The summary of this review is: READY pg. 13, "Opensource" -> "Open source" pg. 14 "decicions" -> "decisions" This document provides a definition of what end-to-end encryption (e2ee) means with respect to existing Internet security mechanisms and protocols, and how the security properties provided by these mechanism and protocols align with user expectations around privacy and confidentiality in light of RFC8890 ("The Internet is for End Users"). It is an improvement on the previous version in that it strenghtens some requirements, i.e. upgrades some SHOULDs to MUSTs, and clarifies others as MAYs. As it notes in its Security Considerations: "Because some policy decisions may affect the security of the internet, a clear and shared definition of end to end encrypted communication is important in policy related discussions. This document aims to provide that clarity." I believe this document correctly captures IETF concensus on e2ee. Derrell