Re: [TLS] Re: [iesg] Appeal Under RFC 9945 Section 4.1: Moderation of D. J. Bernstein During WG Last Call

Nathanael Ritz <[email protected]> Sun, 5 Jul 2026 14:15:39 -0600
Newsgroups gmane.ietf.general
Message-ID <CAHxYnaPig5LtaX9pdsTyeEz1HRunNuPziT4YYF0C=Gdyz06L7g@mail.gmail.com>
-TLSWG +IETF general

Hi,

Top posting. There's enough going on in the TLSWG and this email isn't
really about an appeal made to the IESG at [6] either. So absent any other
avenue, I am bringing my comments here to address Usama's comments shared
at [7].

First, I did not have any deep trouble with what Usama said in the message
at [0]. While I used the message as one concrete example to indicate that
DJB's footnote had a demonstrable impact in on-list conversations, I did
not intend to imply or suggest that Usama experienced any special or
significant difficulty when he wrote his comment at [0], either.

Nevertheless, Usama has now directly explained his position and background
regarding my example for the record. Anyway, I believe Ekr is correct that
these meta conversations about process, conducted this way are unhelpful,
and I regret stepping into that conversation as I did. I have been advised
that I should perhaps be less responsive on-list, and I appreciate this
email is not an illustration of that. That said, I am still going to try
somehow to take care to be more "conservative in what [I] do" moving
forward.

I believe that's all I wanted to communicate.

Sincerely,
Nathanael

[6] https://mailarchive.ietf.org/arch/msg/tls/sHBgSkN_EMzNB9hr1Jiq6kxroOY/

[7] https://mailarchive.ietf.org/arch/msg/tls/iJLHSWTXGPZeIk_FO2XC5n_a4ZE/

On Sun, 5 Jul 2026 at 13:25, Muhammad Usama Sardar <
[email protected]> wrote:

> Hi Ekr,
>
> I wholeheartedly agree with you and have a lot of respect for you. But I
> deeply apologize for not following your plea because the record needs a
> factual correction here. A WG participant has *repeatedly* misrepresented
> my position. Despite my previous complaint to the chairs [2] and a reminder
> by the chairs [3], this is still not stopping. If someone has deep trouble
> with something I said, I once again kindly ask to please double-check it
> with me off-list first before attributing positions to me on list that I
> absolutely do not hold.
>
> ===
>
> Hi all,
>
> Without taking any position on any of the items in the appeal, I would
> like to correct the record since I have been misrepresented here as "an
> example."
>
> I have to wrap up my drafts until the cutoff, so I don't have further time
> for back-and-forth on this matter.
> On 03.07.26 21:09, Nathanael Ritz wrote:
>
> On Tue, 30 Jun 2026 at 12:53, Andrew Lee <[email protected]> wrote:
> > IV. A footnote does not constitute disruption
> >
>
> If you are curious if this uncertainty really truly manifests, an example
> is present here [0] where the participant goes out of their way to confirm
> with DJB that quoting him is permissible, stating in part: "Quoting below
> as per your permission in [1]." As I see it, the presence of that
> disclaimer appears unique to DJB's technical input, and represents a
> genuine, non-renewable (read: "disruptive") investment of time.
>
> How much *genuine, non-renewable investment of time* do folks think it
> took me to write my 7-word phrase that is quoted here? I did not time it
> when I wrote but I am pretty sure anything above a few seconds would be
> quite an exaggeration. And it was one-time permission, which I don't need
> to re-attest each and every time. I would expect D.J.Bernstein to inform me
> when something changes in his notices that invalidate the existing
> permission.
>
[NR]

> Now compare this honestly with how much time it takes me to correct the
> record that Nathanael keeps misrepresenting. Respectfully, much more than
> that. So ironically, contrary to what is represented in the above,
> Nathanael is the one who is consuming my "genuine, non-renewable investment
> of time" on the list.
>
> Besides, in my understanding, the decision to declare "Including derivate
> work notices" as disruptive has been done by officers of the IESG [4]. As I
> am not on the IESG, I am not responsible for it and have absolutely nothing
> to do with this matter. I would appreciate not being drawn into this
> matter, as I had no involvement in that IESG decision. As I understand,
> chairs are just following [4] and keep reminding us (almost) every month
> [5]. It is also my understanding that if D. J. Bernstein will send an email
> without these notices, chairs would let his email go through.
>
> While we are on this topic, let me also clarify my perspective. While I do
> have a strong difference of opinion with D. J. Bernstein in that I consider
> the formal proof for ML-KEM as sufficient and he does not, I acknowledge
> his contributions and have respect for his opinion. One of the things I
> have learnt from him during ML-DSA discussion is the SUF-CMA vs. EUF-CMA,
> which I think I have misunderstood for quite a long time. So FWIW, I do
> believe he is making technical contributions to the WG. I have also not
> been able to formally disprove any of his claimed technical arguments. So I
> have no reason to believe he is technically wrong. My only substantial
> technical concern with him regarding ML-KEM is that he does not show me a
> concrete attack.
>
> My substantial procedural concern with him in [0] quoted here was not his
> notice at all but his tone toward John. I am not a lawyer and wasn't able
> to make sense of his notice as to whether it allows me to quote or not.
> That's the reason I asked for permission in the first place. Given his
> attestation, his notice does not bother me at all, as I choose not to read
> it.
>
> ===
>
> Unless I have missed something in the bunch of emails:
>
>    - nobody from the opponents have shown a concrete attack on standalone
>    ML-KEM in TLS
>    - nobody from the proponents have concrete evidence for me to see how
>    many bits of X25519 CRQC is actually going to break.
>
> Hence, I stay 'no opinion' on WGLC.
>
> Given the heat the three codepoint drafts have produced, in IETF 126, I'll
> propose the idea to make a new WG CryptTLS for all such codepoint drafts to
> happen in that WG, so that we can focus our energy on TLS extensions. As I
> understand Sofia to be saying, a typical TLS participant is not a
> cryptographer and TLS is not a good place for such debates. We have many
> new members who seem to be interested in such debates, so forming a new WG
> may be good. We can offer the proposed WG the formal analysis services if
> they would need.
>
>
> Time spent navigating procedural hurdles instead of focusing on the
> technical point.
>
> Exactly. Correcting repeated misrepresentations of my position is itself
> time spent on procedural matters rather than technical discussion.
>
> Sincerely,
>
> -Usama
>
> [0] https://mailarchive.ietf.org/arch/msg/tls/LvjJJGQIUER1k__G0Gorak8YfJQ/
>
> [1]
> https://mailarchive.ietf.org/arch/msg/last-call/oKrCjFfDUYoePOVSyWQ-URQU9Fk/
>
> [2] https://mailarchive.ietf.org/arch/msg/tls/jy1vb5EQvC2fItf5n8iTmahwotg/
>
> [3] https://mailarchive.ietf.org/arch/msg/tls/r_pkryXALfFLtMccvE6Mnj4wrhQ/
>
> [4]
> https://datatracker.ietf.org/doc/statement-iesg-statement-on-clarifying-derivative-works-rights/
>
> [5] https://mailarchive.ietf.org/arch/msg/tls/cEUcbe27qZUBnapkDMExOmHC5I4/
>


---------- Forwarded message ---------
From: Nathanael Ritz <[email protected]>
Date: Fri, 3 Jul 2026 at 13:09
Subject: Re: [TLS] [iesg] Appeal Under RFC 9945 Section 4.1: Moderation of
D. J. Bernstein During WG Last Call
To: Andrew Lee <[email protected]>
Cc: Livingood, Jason <[email protected]>, Dhruv Dhody <
[email protected]>, TLS List <[email protected]>


Andrew,

On Fri, 3 Jul 2026 at 12:30, Andrew Lee <[email protected]> wrote:

> <snip>
> Nathanael put it well when he said, "friction is a feature the community
> relies on to help shape ..." but it is "a bug in the process ... when that
> friction is applied during a time limited community event such as Last
> Call."
>
>
I want to be very clear that I am confident this goes both ways. To wit, I
want to be understood that I was trying to say that "when [someone like DJB
applies the other kind of friction seperate from technical debate] during a
time limited community event such as Last Call," I believe it "represents a
bug in the process" that could be misused.

That is to say, I think that perhaps DJB could have included a persistent
footnote stating that he has an active dispute/appeal/whatever with the
IETF/IESG/IAB/LLC/ISOC and so on. Perhaps he could further clarify that his
footnotes are not intended to cast doubt on the ability of other
participants' ability to safely engage with threads where his previous
input to the mailing may have been misquoted or reshaped (by whomever).

By insisting on engaging with the highest possible friction—for example, by
incorporating both his technical judgement alongside his procedural
misgivings as presented in his message—during an event like Last Call
creates a genuine technical, procedural and social dilemma. For example,
your appeal.

On Tue, 30 Jun 2026 at 12:53, Andrew Lee <[email protected]> wrote:
> IV. A footnote does not constitute disruption
>

If you are curious if this uncertainty really truly manifests, an example
is present here [0] where the participant goes out of their way to confirm
with DJB that quoting him is permissible, stating in part: "Quoting below
as per your permission in [1]." As I see it, the presence of that
disclaimer appears unique to DJB's technical input, and represents a
genuine, non-renewable (read: "disruptive") investment of time. Time spent
navigating procedural hurdles instead of focusing on the technical point.

Best regards,
Nathanael

[0] https://mailarchive.ietf.org/arch/msg/tls/LvjJJGQIUER1k__G0Gorak8YfJQ/

[1]
https://mailarchive.ietf.org/arch/msg/last-call/oKrCjFfDUYoePOVSyWQ-URQU9Fk/


On Fri, 3 Jul 2026 at 12:30, Andrew Lee <[email protected]> wrote:

> Dear Jason,
>
> With all due respect, whether Dr. Bernstein is blameless is not the
> question before the IESG.
>
> The question is whether a two (2) business day moderation delay is
> compatible with a time-limited vote that the IAB itself identified as the
> proper venue for his objections.
>
> Two days in internet time is an eternity. A response to a statement is
> orphaned and lost. Further, in a two week limited process, it's 14.3% of
> the entire window... per message! If you think the 50-100us added time of
> the X25519+HKDF is expensive, then let me tell you, two days is
> 172,800,000,000us.
>
> Nathanael put it well when he said, "friction is a feature the community
> relies on to help shape ..." but it is "a bug in the process ... when that
> friction is applied during a time limited community event such as Last
> Call."
>
> Best,
> Andrew
>
>
> On Jul 3, 2026, at 9:07 AM, Nathanael Ritz <[email protected]> wrote:
>
> Below with [NR]:
>
> On Fri, Jul 3, 2026 at 9:14 AM Livingood, Jason <
> [email protected]> wrote:
>
>> *From: *Nathanael Ritz <[email protected]>
>>
>> > [AL] The real question before the IESG remains to be answered. The IAB
>> identified WGLC as the venue for Dr. Bernstein's technical objections, and
>> the chairs have restricted his ability to participate in that venue during
>> a vote with time limit. Whether the moderation is theoretically permissible
>> doesn't resolve whether it's compatible with the IAB's own guidance.
>>
>>
> [NR] There’s just the one > marker here, so I want to mention that the
> “real question” was written by Andrew Lee [AL], not myself. I’ve annotated
> this email throughout for clarity.
>
> [NR] I believe Andrew’s appeal was brought forward in good faith, even if
> misguided. I do think there is value in considering the impact of
> moderation against a community time limit.
>
> [JL] Dan’s approach is not blameless here; he understands the rules and
>> norms IETF and by all appearances goes out of his way to not follow them.
>> This results in things like being moderated, with the end result all the
>> discussion tends to be about side issues of process and this and that,
>> rather than the core technical issue he appears to want to address (pure vs
>> hybrid). That diversion is a real shame and ends up being a waste of the
>> IETF’s collective time.
>>
>
> [NR] In my opinion, while he is not without his own reasons, DJB appears
> to have taken the highest mode of friction possible to communicate his
> position. While friction is a feature the community relies on to help shape
> high-quality technical proposals, there’s a different kind of friction I
> see here that is indeed seemingly entirely avoidable. In this other case, I
> think that represents a bug in the process, especially when that friction
> is applied during a time limited community event such as Last Call.
>
>
>> JL
>>
>
> Cheers,
> Nathanael
>
>
>
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
>