Re: Affiliation disclosure in security WGs
"Rob Wilton \(rwilton\)" <[email protected]> Wed, 1 Jul 2026 06:30:35 +0000
| Newsgroups | gmane.ietf.general |
|---|---|
| Message-ID | <DM4PR11MB5469649465F9B2377EFC5A9DB5F62@DM4PR11MB5469.namprd11.prod.outlook.com> |
HI Andrew, Apologies for the typos. In response to your questions: Re 1). I meant "some participants may not be able to disclose." I'm not aware of anyone who works for Cisco, or on behalf of Cisco, that participates in the IETF and is unable to disclose who they work for. Re 2) For participants who speak at the mic, send comments to the list, or are WG chairs for the network management related WGs that I participate in, then I have a rough idea of who are consultants and who they are likely consulting for - in many cases this is obvious from which drafts they are supporting. Re 3) The "Responsible AD" is the AD assigned to oversee a given WG and is listed in the IETF datatracker. If you think that ADs are not being fair and balanced then based on my personal experience of when I was recently an AD I believe that you are very mistaken. In my experience, the IESG goes out of their way to ensure that the IETF process has been followed correctly and fairly and ensure that all views are heard. Of course, that does not mean that what they approve necessarily matches up with what you want, nor does it mean that the process is broken. When judging IETF consensus, I would expect them to give more weight towards those who actively constructively participate and comment in the WG and IETF in general versus those just pop up to say +1 or "I also object". Kind regards, Rob From: Andrew Lee <[email protected]> Date: Monday, 29 June 2026 at 17:46 To: Rob Wilton (rwilton) <[email protected]> Cc: Brian E Carpenter <[email protected]>; [email protected] <[email protected]> Subject: Re: Affiliation disclosure in security WGs Dear Rob, Thank you for the thoughtful response. With that said, I think some of the points you mentioned are exactly why we need a disclosure policy: 1) “some my (sic) contractually be unable to disclose” This is the very definition of an undercover agent. Did you mean to say “may” or did you omit the word “colleagues?" 2) “WG chairs are expected to take into account participants rough affiliates” As there is no mandatory disclosure policy, this is an impossibility and, further, could result to false accusations against those who are clearly not affiliated with any of these organizations. 3) "responsible ADs” The entire IETF mailing list and interested persons externally throughout the internet has learned that this is an oxymoron. I truly feel sorry for the minority, as it seems today, that do deserve the right to said adjective. I appreciate you using your corporate e-mail address. That said, I think that disclosure would be more than just supplying your e-mail and more an exercise of determining just how much of your compensation is a result, both directly and indirectly, of activities relating to work for these agencies. Best, Andrew On Jun 29, 2026, at 5:43 AM, Rob Wilton (rwilton) <[email protected]> wrote: Hi Andrew, In the past I have encouraged a participant disclosure policy, but I have a feeling that there are also reasons that this can get complicated (e.g., some my contractually be unable to disclose). I think that the compromise (which may have never been actioned) was to have an extra field in the data tracker profile to allow an individual to optionally declare their affiliation, but without mandating it. Perhaps if enough people did this then it would effectively achieve what you are looking for without any additional rules. It is worth noting that the IESG already has a disclosure policy, i.e., https://www.ietf.org/about/groups/iesg/iesg-coi-policy/ because they can have a much more considerable impact on the standards process. Within the rest of the process, my understanding is that the WG chairs are expected to take into account participants rough affiliations. E.g., if everyone from one organisation supports a draft, and nobody from any other organisation does, then it is questionable whether there is really consensus. In the case of WG chairs, I would expect that the responsible ADs to be aware of their WG chair's affiliations and to also take that into consideration. In my experience, folks often will try to recuse themselves if there is even a perception of a CoI. Note, finally, this is why I use my corporate email address in all my IETF communications, i.e., to make it very clear of what my affiliation is. Kind regards, Rob