It appears to me as if the security community in IETF can't offer a good password based security protocol.
> > Anything beyond TLS+PLAIN seem to me be either surrounded with IPR > concerns (SPEKE, SRP); [...]
Would it be fair to take that as meaning you'd be supportive of new work being done here on things like SPEKE if it were not "surrounded by IPR concerns"?