Re: Affiliation disclosure in security WGs

John C Klensin <[email protected]> Mon, 29 Jun 2026 09:10:32 -0400
Newsgroups gmane.ietf.general
Message-ID <66433E5359E3AFD99400D8F9@JcK-HP5>
On Sun, 28 June 2026 21:09 UTC Brian E Carpenter
<[email protected]> wrote...
 
> Andrew,
> 
> Without commenting on the question of disclosure as such, I'd
> like to point out that the conduct guidelines (RFC 7154, BCP
> 54) already make it very clear that we do not participate on
> behalf of our employers or clients:
> 
>       "IETF participants use their best engineering judgment
> to find the best solution for the whole Internet, not
> just the best solution for any particular network,
> technology, vendor, or user.  While we all have ideas
> that may stand improvement from time to time, no one
> shall ever knowingly contribute advice or text that would make
> a standard technically inferior."
> 
> RFC 7154 is the first citation in the Note Well, so ignorance
> is no excuse. Of course, proving that an individual
> participant has intentionally failed to follow this guideline
> is extremely hard, and I don't think that knowing their
> affiliation has any evidentiary value in this.

Brian,

Also without commenting on the question of disclosure, I
certainly agree with that statement and have quoted it and
pointed to it multiple times.  However let's also remember
several things that point to its aspirational nature.  For
example...

* We've had multiple instances in which one or more companies
have been willing to generously support multiple employees to
volunteer for time-consuming and often costly IETF roles.  That
support can be attributable to strong belief the IETF and its
activities with no expectation that the individuals, if
appointed, will favor company positions or even that the company
might advertise the number of people in IETF leadership roles to
demonstrate its own importance (and potential leverage).  At the
same time, there has been enough concern about the appearance of
problematic behavior of that general type that we have rules
limiting the number of people from one organization who can
simultaneously serve on, e.g., the Nomcom or IESG.   If we could
somehow guarantee that people would always act independent of
affiliation or sources of support we would not need such rules.

* Many companies have strong business models and corporate
cultures built around particular technical positions and
objectives.  Most of those tie hiring and retention practices to
those models and cultures.  While it is nice to assume that
people employed and supported by such companies will not have
absorbed their cultures but, instead, will exercise "best
engineering judgment to find the best solution for the whole
Internet", it is often unrealistic to assume that the day-to-day
implications of their work environments will not affect that
best judgment. 

* Reflecting your last paragraph above, it is even harder to
prove unintentional influence from the culture of day jobs on
participant judgment, making those judgments less about their
independent engineering decisions than that to which the above
aspires.  I note, fwiw, that the recent MODPOD effort has no
provision for dealing with people who appear to be acting
inappropriately with regard to those "best engineering judgment"
criteria.  Indeed, someone making a claim that someone else is
behaving improperly along that dimension could easily be accused
of making personal attacks and being disruptive, creating a
"punish the victim" environment.

* And, again fwiw, the paragraph you cite does not appear to me
to make any provision at all about decision-making in procedural
matters or even in matters that are not narrowly
engineering-based, including societal issues.  As an extreme
example involving security issues, while questions of how to
provide maximum privacy are likely to be engineering issues,
questions of the importance of privacy relative to other
objectives are likely social policy ones.  In many cases,
optimizing choices about a standard around such policy goals
might actually make it technically inferior if judged purely on
a technical engineering basis.

     john