Affiliation disclosure in security WGs
Andrew Lee <[email protected]> Sun, 28 Jun 2026 13:27:28 -0700
| Newsgroups | gmane.ietf.general |
|---|---|
| Message-ID | <CACSbMK=9Gb3cwHotu_dc-4GY2MnG_sdtvx6gc_KCogaF894yVg@mail.gmail.com> |
To the IETF Participants, First and foremost, thank you for taking the time to participate in this forum. Your contributions have an outsized impact and yet from a congratulatory perspective, often go unnoticed. I'm sure I speak on behalf of everyone when I say thank you... Thank you. I also wanted to address some issues that have come to light. The IETF requires participants to disclose patents that could affect technologies under discussion, because hidden encumbrances undermine the consensus process when participants can't make informed technical judgments without knowing these influences may exist. Anyone unwilling to disclose is expected to recuse themselves [1]. The IETF's guidelines for conduct ask participants to use their best engineering judgment for the whole Internet, period [2]. The community has also already declared by consensus that pervasive monitoring, like nation-state surveillance, is an attack on Internet privacy, and that the attacker's motivation is irrelevant to how we mitigate it in our protocols [3]. Additionally, the IETF has formally refused to build wiretapping capabilities into standards [4]. In other words, we harden the protocols against nation-state adversaries [5], but we have no mechanism to address undisclosed organizational interests that conflict with producing sound technical outcomes. Dual_EC_DRBG is what happens when that gap gets exploited. NIST overhauled its own standards process after the fact [6]. Recent discussions in IETF security related working groups have exposed this gap in practice. Without mandatory disclosure, affiliation concerns can only surface as ad hoc accusations [7], which are unfair to the accused and unverifiable by anyone else. Worse, working group chairs have sole discretion over what constitutes a conduct violation and can selectively enforce conduct rules to suppress some facts while allowing other opinions. A chair can let unsubstantiated affiliation accusations stand unchallenged while shutting down substantive technical objections or process concerns under the same conduct policy. There is no check on this, and chairs themselves have no disclosure requirement. IEEE 802 already requires participants to declare their affiliation, defined as any entity that financially or materially supports the individual's participation [8]. Yet, the IETF does not. I'm not proposing that anyone be excluded or stratified, ever. The community should consider whether a disclosure norm is warranted, for participants in security-relevant working groups and especially for working group chairs and IETF directors, and whether the existing intellectual property disclosure framework could serve as a model for it. Sincerely, Andrew [1] https://www.rfc-editor.org/info/rfc8179 [2] https://www.rfc-editor.org/info/rfc7154 [3] https://www.rfc-editor.org/info/rfc7258 [4] https://www.rfc-editor.org/info/rfc2804 [5] NSA, GCHQ, and other SIGINT type agencies [6] https://csrc.nist.gov/nist-cyber-history/cryptography/chapter [7] "Hey those 3-5 voters are on team internet" or "Hey they are with the NSA" [8] https://www.rfc-editor.org/info/rfc7241