Re: Affiliation disclosure in security WGs

Andrew Lee <[email protected]> Sun, 28 Jun 2026 14:29:58 -0700
Newsgroups gmane.ietf.general
Message-ID <[email protected]>
Dear Brian,

Respectfully, I’d push back on the no “evidentiary value.” While intent cannot be inferred, someone’s affiliation can sometimes influence their decisions, even in good faith. For example, assume a man from Cupland is not aware of the existence of a bowl. He may suggest using a cup for soup in good faith.

Disclosures let the community account for these possibilities, the same way IPR does with RFC 8179.

Best,
Andrew

> On Jun 28, 2026, at 2:09 PM, Brian E Carpenter <[email protected]> wrote:
> 
> Andrew,
> 
> Without commenting on the question of disclosure as such, I'd like to point out that the conduct guidelines (RFC 7154, BCP 54) already make it very clear that we do not participate on behalf of our employers or clients:
> 
>     "IETF participants use their best engineering judgment to find the
>      best solution for the whole Internet, not just the best solution
>      for any particular network, technology, vendor, or user.  While we
>      all have ideas that may stand improvement from time to time, no
>      one shall ever knowingly contribute advice or text that would make
>      a standard technically inferior."
> 
> RFC 7154 is the first citation in the Note Well, so ignorance is no excuse. Of course, proving that an individual participant has intentionally failed to follow this guideline is extremely hard, and I don't think that knowing their affiliation has any evidentiary value in this.
> 
> Regards/Ngā mihi
>   Brian Carpenter
>