Re: Affiliation disclosure in security WGs

"Rob Wilton \(rwilton\)" <[email protected]> Mon, 29 Jun 2026 12:43:28 +0000
Newsgroups gmane.ietf.general
Message-ID <LV8PR11MB8536EBD5EA065A0EC6634C3AB5E82@LV8PR11MB8536.namprd11.prod.outlook.com>
Hi Andrew,

In the past I have encouraged a participant disclosure policy, but I have a feeling that there are also reasons that this can get complicated (e.g., some my contractually be unable to disclose).  I think that the compromise (which may have never been actioned) was to have an extra field in the data tracker profile to allow an individual to optionally declare their affiliation, but without mandating it.  Perhaps if enough people did this then it would effectively achieve what you are looking for without any additional rules.

It is worth noting that the IESG already has a disclosure policy, i.e., https://www.ietf.org/about/groups/iesg/iesg-coi-policy/ because they can have a much more considerable impact on the standards process.

Within the rest of the process, my understanding is that the WG chairs are expected to take into account participants rough affiliations.  E.g., if everyone from one organisation supports a draft, and nobody from any other organisation does, then it is questionable whether there is really consensus.

In the case of WG chairs, I would expect that the responsible ADs to be aware of their WG chair's affiliations and to also take that into consideration.  In my experience, folks often will try to recuse themselves if there is even a perception of a CoI.

Note, finally, this is why I use my corporate email address in all my IETF communications, i.e., to make it very clear of what my affiliation is.

Kind regards,
Rob


From: Andrew Lee <[email protected]>
Date: Sunday, 28 June 2026 at 23:31
To: Brian E Carpenter <[email protected]>
Cc: [email protected] <[email protected]>
Subject: Re: Affiliation disclosure in security WGs

Dear Brian,

Respectfully, I’d push back on the no “evidentiary value.” While intent cannot be inferred, someone’s affiliation can sometimes influence their decisions, even in good faith. For example, assume a man from Cupland is not aware of the existence of a bowl. He may suggest using a cup for soup in good faith.

Disclosures let the community account for these possibilities, the same way IPR does with RFC 8179.

Best,
Andrew

On Jun 28, 2026, at 2:09 PM, Brian E Carpenter <[email protected]> wrote:

Andrew,

Without commenting on the question of disclosure as such, I'd like to point out that the conduct guidelines (RFC 7154, BCP 54) already make it very clear that we do not participate on behalf of our employers or clients:

    "IETF participants use their best engineering judgment to find the
     best solution for the whole Internet, not just the best solution
     for any particular network, technology, vendor, or user.  While we
     all have ideas that may stand improvement from time to time, no
     one shall ever knowingly contribute advice or text that would make
     a standard technically inferior."

RFC 7154 is the first citation in the Note Well, so ignorance is no excuse. Of course, proving that an individual participant has intentionally failed to follow this guideline is extremely hard, and I don't think that knowing their affiliation has any evidentiary value in this.

Regards/Ngā mihi
  Brian Carpenter