Per @ekr:

We are generally in favor of this effort, however, we request submission to WICG.

We also have some concerns about the specific implementation. In particular, WebCrypto took a real “no seatbelts” design approach which we now think is wrong. That's perpetuated here and we’d like to revisit that.

It would probably be good to add some other algorithms as well (ChaCha/Poly, HPKE).

None of the existing groups really seem appropriate so maybe we need to reboot WebCrypto (whether in W3C or WHATWG). Not sure if this needs incubation, but in the interest of getting it out of a private repo, please submit to WICG while we figure out the rest.

