Re: Affiliation disclosure in security WGs
John C Klensin <[email protected]> Mon, 29 Jun 2026 09:10:32 -0400
| Newsgroups | gmane.ietf.general |
|---|---|
| Message-ID | <66433E5359E3AFD99400D8F9@JcK-HP5> |
On Sun, 28 June 2026 21:09 UTC Brian E Carpenter <[email protected]> wrote... > Andrew, > > Without commenting on the question of disclosure as such, I'd > like to point out that the conduct guidelines (RFC 7154, BCP > 54) already make it very clear that we do not participate on > behalf of our employers or clients: > > "IETF participants use their best engineering judgment > to find the best solution for the whole Internet, not > just the best solution for any particular network, > technology, vendor, or user. While we all have ideas > that may stand improvement from time to time, no one > shall ever knowingly contribute advice or text that would make > a standard technically inferior." > > RFC 7154 is the first citation in the Note Well, so ignorance > is no excuse. Of course, proving that an individual > participant has intentionally failed to follow this guideline > is extremely hard, and I don't think that knowing their > affiliation has any evidentiary value in this. Brian, Also without commenting on the question of disclosure, I certainly agree with that statement and have quoted it and pointed to it multiple times. However let's also remember several things that point to its aspirational nature. For example... * We've had multiple instances in which one or more companies have been willing to generously support multiple employees to volunteer for time-consuming and often costly IETF roles. That support can be attributable to strong belief the IETF and its activities with no expectation that the individuals, if appointed, will favor company positions or even that the company might advertise the number of people in IETF leadership roles to demonstrate its own importance (and potential leverage). At the same time, there has been enough concern about the appearance of problematic behavior of that general type that we have rules limiting the number of people from one organization who can simultaneously serve on, e.g., the Nomcom or IESG. If we could somehow guarantee that people would always act independent of affiliation or sources of support we would not need such rules. * Many companies have strong business models and corporate cultures built around particular technical positions and objectives. Most of those tie hiring and retention practices to those models and cultures. While it is nice to assume that people employed and supported by such companies will not have absorbed their cultures but, instead, will exercise "best engineering judgment to find the best solution for the whole Internet", it is often unrealistic to assume that the day-to-day implications of their work environments will not affect that best judgment. * Reflecting your last paragraph above, it is even harder to prove unintentional influence from the culture of day jobs on participant judgment, making those judgments less about their independent engineering decisions than that to which the above aspires. I note, fwiw, that the recent MODPOD effort has no provision for dealing with people who appear to be acting inappropriately with regard to those "best engineering judgment" criteria. Indeed, someone making a claim that someone else is behaving improperly along that dimension could easily be accused of making personal attacks and being disruptive, creating a "punish the victim" environment. * And, again fwiw, the paragraph you cite does not appear to me to make any provision at all about decision-making in procedural matters or even in matters that are not narrowly engineering-based, including societal issues. As an extreme example involving security issues, while questions of how to provide maximum privacy are likely to be engineering issues, questions of the importance of privacy relative to other objectives are likely social policy ones. In many cases, optimizing choices about a standard around such policy goals might actually make it technically inferior if judged purely on a technical engineering basis. john