Re: Affiliation disclosure in security WGs
Orie <[email protected]> Mon, 29 Jun 2026 12:23:03 -0500
| Newsgroups | gmane.ietf.general |
|---|---|
| Message-ID | <CAMzqgoz9iDwS3F+X2gsk8iM2RNPebLS9Vgmn63T9qDT7Zxv6xA@mail.gmail.com> |
Hi Andrew, The IETF is not like other SDOs; some have stricter guidelines regarding disclosure of funding sources, or they only allow participation on behalf of certain entities. Our process's inclusiveness is a feature, it's what enabled RFC7258. If the problem you are trying to solve is that the motive behind certain technical perspectives is not always clear, I think the solution might be to focus on arguing whether the technical perspective is sound, rather than guessing participants' motives based on their affiliation, or guessing their perspective is correct, based on appeals to authority. If we changed the rules to require funding disclosure for participation, someone with malicious motives could almost certainly secure funding from a source that appears innocuous. I don't see how what you are advocating for would make the internet work better. However, if you feel strongly about this, I suggest you write a draft, or participate in the nomcom, perhaps you can convince the community there is a benefit to a process change. Regards, OS On Mon, Jun 29, 2026 at 10:49 AM Andrew Lee <[email protected]> wrote: > Dear Rob, > > Thank you for the thoughtful response. > > With that said, I think some of the points you mentioned are exactly why > we need a disclosure policy: > > 1) “some my (sic) contractually be unable to disclose” > > This is the very definition of an undercover agent. Did you mean to say > “may” or did you omit the word “colleagues?" > > 2) “WG chairs are expected to take into account participants rough > affiliates” > > As there is no mandatory disclosure policy, this is an impossibility and, > further, could result to false accusations against those who are clearly > not affiliated with any of these organizations. > > 3) "responsible ADs” > > The entire IETF mailing list and interested persons externally throughout > the internet has learned that this is an oxymoron. I truly feel sorry for > the minority, as it seems today, that do deserve the right to said > adjective. > > I appreciate you using your corporate e-mail address. That said, I think > that disclosure would be more than just supplying your e-mail and more an > exercise of determining just how much of your compensation is a result, > both directly and indirectly, of activities relating to work for these > agencies. > > Best, > Andrew > > > On Jun 29, 2026, at 5:43 AM, Rob Wilton (rwilton) <[email protected]> > wrote: > > > Hi Andrew, > > In the past I have encouraged a participant disclosure policy, but I have > a feeling that there are also reasons that this can get complicated (e.g., > some my contractually be unable to disclose). I think that the compromise > (which may have never been actioned) was to have an extra field in the data > tracker profile to allow an individual to optionally declare their > affiliation, but without mandating it. Perhaps if enough people did this > then it would effectively achieve what you are looking for without any > additional rules. > > It is worth noting that the IESG already has a disclosure policy, i.e., > https://www.ietf.org/about/groups/iesg/iesg-coi-policy/ because they can > have a much more considerable impact on the standards process. > > Within the rest of the process, my understanding is that the WG chairs > are expected to take into account participants rough affiliations. E.g., > if everyone from one organisation supports a draft, and nobody from any > other organisation does, then it is questionable whether there is really > consensus. > > In the case of WG chairs, I would expect that the responsible ADs to be > aware of their WG chair's affiliations and to also take that into > consideration. In my experience, folks often will try to recuse themselves > if there is even a perception of a CoI. > > Note, finally, this is why I use my corporate email address in all my IETF > communications, i.e., to make it very clear of what my affiliation is. > > Kind regards, > Rob > > > >