Affiliation disclosure in security WGs

Andrew Lee <[email protected]> Sun, 28 Jun 2026 13:27:28 -0700
Newsgroups gmane.ietf.general
Message-ID <CACSbMK=9Gb3cwHotu_dc-4GY2MnG_sdtvx6gc_KCogaF894yVg@mail.gmail.com>
To the IETF Participants,

First and foremost, thank you for taking the time to participate in this
forum. Your contributions have an outsized impact and yet from a
congratulatory perspective, often go unnoticed.

I'm sure I speak on behalf of everyone when I say thank you...

Thank you.

I also wanted to address some issues that have come to light. The IETF
requires participants to disclose patents that could affect technologies
under discussion, because hidden encumbrances undermine the consensus
process when participants can't make informed technical judgments without
knowing these influences may exist. Anyone unwilling to disclose is
expected to recuse themselves [1].

The IETF's guidelines for conduct ask participants to use their best
engineering judgment for the whole Internet, period [2]. The community has
also already declared by consensus that pervasive monitoring, like
nation-state surveillance, is an attack on Internet privacy, and that the
attacker's motivation is irrelevant to how we mitigate it in our protocols
[3]. Additionally, the IETF has formally refused to build wiretapping
capabilities into standards [4].

In other words, we harden the protocols against nation-state adversaries
[5], but we have no mechanism to address undisclosed organizational
interests that conflict with producing sound technical outcomes.
Dual_EC_DRBG is what happens when that gap gets exploited. NIST overhauled
its own standards process after the fact [6].

Recent discussions in IETF security related working groups have exposed
this gap in practice. Without mandatory disclosure, affiliation concerns
can only surface as ad hoc accusations [7], which are unfair to the accused
and unverifiable by anyone else. Worse, working group chairs have sole
discretion over what constitutes a conduct violation and can selectively
enforce conduct rules to suppress some facts while allowing other opinions.
A chair can let unsubstantiated affiliation accusations stand unchallenged
while shutting down substantive technical objections or process concerns
under the same conduct policy. There is no check on this, and chairs
themselves have no disclosure requirement.

IEEE 802 already requires participants to declare their affiliation,
defined as any entity that financially or materially supports the
individual's participation [8]. Yet, the IETF does not.

I'm not proposing that anyone be excluded or stratified, ever. The
community should consider whether a disclosure norm is warranted, for
participants in security-relevant working groups and especially for working
group chairs and IETF directors, and whether the existing intellectual
property disclosure framework could serve as a model for it.

Sincerely,
Andrew

[1] https://www.rfc-editor.org/info/rfc8179
[2] https://www.rfc-editor.org/info/rfc7154
[3] https://www.rfc-editor.org/info/rfc7258
[4] https://www.rfc-editor.org/info/rfc2804
[5] NSA, GCHQ, and other SIGINT type agencies
[6] https://csrc.nist.gov/nist-cyber-history/cryptography/chapter
[7] "Hey those 3-5 voters are on team internet" or "Hey they are with the
NSA"
[8] https://www.rfc-editor.org/info/rfc7241