Re: Affiliation disclosure in security WGs
Donald Eastlake <[email protected]> Mon, 29 Jun 2026 11:39:21 -0400
| Newsgroups | gmane.ietf.general |
|---|---|
| Message-ID | <CAF4+nEHaXYFNE0Oxx6DSez+346qandpfmPi8HakSCqtxFOX_Eg@mail.gmail.com> |
John Klensin said: "we have rules limiting the number of people from one organization who can simultaneously serve on, e.g., the Nomcom or IESG." The only such rule of which I am aware is for the Nomcom. In particular, there is no such rule for the IESG or IAB or ... Of course, in practice, despite the lack of such rules, Nomcoms (I have served on several including once as chair and once as previous chair) try to avoid affiliation concentration in the IESG, etc., but it depends on what good candidates are available. Furthermore, once someone is selected/installed on, say, the IESG, there is nothing stopping an AD from changing affiliation, including changing to an affiliation which is the same as one or more other ADs. Thanks, Donald =============================== Donald E. Eastlake 3rd 2386 Panoramic Circle, Apopka, FL 32703 USA [email protected] On Mon, Jun 29, 2026 at 9:13 AM John C Klensin <[email protected]> wrote: > > On Sun, 28 June 2026 21:09 UTC Brian E Carpenter > <[email protected]> wrote... > > > Andrew, > > > > Without commenting on the question of disclosure as such, I'd > > like to point out that the conduct guidelines (RFC 7154, BCP > > 54) already make it very clear that we do not participate on > > behalf of our employers or clients: > > > > "IETF participants use their best engineering judgment > > to find the best solution for the whole Internet, not > > just the best solution for any particular network, > > technology, vendor, or user. While we all have ideas > > that may stand improvement from time to time, no one > > shall ever knowingly contribute advice or text that would make > > a standard technically inferior." > > > > RFC 7154 is the first citation in the Note Well, so ignorance > > is no excuse. Of course, proving that an individual > > participant has intentionally failed to follow this guideline > > is extremely hard, and I don't think that knowing their > > affiliation has any evidentiary value in this. > > Brian, > > Also without commenting on the question of disclosure, I > certainly agree with that statement and have quoted it and > pointed to it multiple times. However let's also remember > several things that point to its aspirational nature. For > example... > > * We've had multiple instances in which one or more companies > have been willing to generously support multiple employees to > volunteer for time-consuming and often costly IETF roles. That > support can be attributable to strong belief the IETF and its > activities with no expectation that the individuals, if > appointed, will favor company positions or even that the company > might advertise the number of people in IETF leadership roles to > demonstrate its own importance (and potential leverage). At the > same time, there has been enough concern about the appearance of > problematic behavior of that general type that we have rules > limiting the number of people from one organization who can > simultaneously serve on, e.g., the Nomcom or IESG. If we could > somehow guarantee that people would always act independent of > affiliation or sources of support we would not need such rules. > > * Many companies have strong business models and corporate > cultures built around particular technical positions and > objectives. Most of those tie hiring and retention practices to > those models and cultures. While it is nice to assume that > people employed and supported by such companies will not have > absorbed their cultures but, instead, will exercise "best > engineering judgment to find the best solution for the whole > Internet", it is often unrealistic to assume that the day-to-day > implications of their work environments will not affect that > best judgment. > > * Reflecting your last paragraph above, it is even harder to > prove unintentional influence from the culture of day jobs on > participant judgment, making those judgments less about their > independent engineering decisions than that to which the above > aspires. I note, fwiw, that the recent MODPOD effort has no > provision for dealing with people who appear to be acting > inappropriately with regard to those "best engineering judgment" > criteria. Indeed, someone making a claim that someone else is > behaving improperly along that dimension could easily be accused > of making personal attacks and being disruptive, creating a > "punish the victim" environment. > > * And, again fwiw, the paragraph you cite does not appear to me > to make any provision at all about decision-making in procedural > matters or even in matters that are not narrowly > engineering-based, including societal issues. As an extreme > example involving security issues, while questions of how to > provide maximum privacy are likely to be engineering issues, > questions of the importance of privacy relative to other > objectives are likely social policy ones. In many cases, > optimizing choices about a standard around such policy goals > might actually make it technically inferior if judged purely on > a technical engineering basis. > > john > >