Re: Affiliation disclosure in security WGs
Brian E Carpenter <[email protected]> Tue, 30 Jun 2026 12:21:16 +1200
| Newsgroups | gmane.ietf.general |
|---|---|
| Message-ID | <[email protected]> |
Andrew,
The problem of partisan bias is not limited to the security area. It has often been a plausible suspicion in many other IETF areas, over several decades. In some ways, it's the basic reason behind the rough consesnus model.
Regards/Ngā mihi
Brian
On 30-Jun-26 12:01, Andrew Lee wrote:
> Dear Carsten,
>
> Dual_EC_DRBG was not "vivid imagination." Additionally, the personal remark was unnecessary.
>
> Dear Orie,
>
> I agree we should focus on technical merit. The problem is that participants making technical arguments are being moderated, while participants posting 'I support publication' are counted toward consensus and those attacking the people making technical arguments face no consequences. When the system punishes argument and rewards assertion, "focus on the technical perspective" is empty advice.
>
> Dear S. Moonesamy,
>
> Broad review only works if reviewers are allowed to speak.
>
>
> Again, the IESG already has a conflict disclosure policy. IEEE 802 requires affiliation disclosure from every participant. The question is why security WG chairs and participants have no such requirement?
>
> Sincerely,
> Andrew
>
>> On Jun 29, 2026, at 4:15 PM, S Moonesamy <[email protected]> wrote:
>>
>> Hi Andrew,
>> At 01:27 PM 28-06-2026, Andrew Lee wrote:
>>> I'm not proposing that anyone be excluded or stratified, ever. The community should consider whether a disclosure norm is warranted, for participants in security-relevant working groups and especially for working group chairs and IETF directors, and whether the existing intellectual property disclosure framework could serve as a model for it.
>>
>> There is already a policy for the IESG: https://www.ietf.org/about/groups/iesg/iesg-coi-policy/
>>
>> It's possible to tell whether a working group Chair works for Company A by looking at his/her email address. A working group Chair generally does not take a decision on a draft if he/she is listed as a author. There are probably other scenarios. The practice I am familiar with is to disclose name and affiliation when a person made a statement during a working group meeting. That practice is not documented anywhere.
>>
>> RFC 8179 requires an IPR disclosure. A working group is supposed to use that information when it evaluates an alternative technical solution (RFC 8179, Page 14). Standard Setting Organizations usually have policies on IPR as it's good for the participants to know whether there might be restrictive licenses affecting a standard.
>>
>> There was a discussion about affiliations in 2025: https://mailarchive.ietf.org/arch/msg/ietf/s4BGuUgsCff0hrRqTy4ay9RhR-4/ There was a discussion about that in 2022; it was related to Nomination Committees: https://mailarchive.ietf.org/arch/msg/ietf/n48hz9ahDvvT01F5dxDIBonB-XY/ Is the issue that a participant will:
>>
>> (a) receive a more/less favorable response because of his/her affiliation;
>>
>> (b) do something technical good/bad because of his/her affiliation?
>>
>> Commenting on (b), it would be less likely for the technical bad to get through if there was open and broad review of a draft.
>>
>> Regards,
>> S. Moonesamy
>