Re: Conflict of Interest: IETF and the NSA – Fwd: [Ssh] Complaint to SSHM chairs
Orie <[email protected]>
| Newsgroups | gmane.ietf.general,gmane.ietf.tls |
|---|---|
| Message-ID | <CAMzqgowqCNz7x4y5h0ZF0pKZgKSzLZGP7MjtqiFwTu709QZmLg@mail.gmail.com> |
<snip> (with apologies to the TLS list, this will be my only email). > Nevertheless, in flagrant violation of fundamental security engineering principles (including an RFC, see link above), a non-hybrid approach was forced through. IETF specifications are voluntary to implement, and we operate on rough consensus and running code. Running code exists for both pure and hybrid crypto. By trying to forbid pure PQ algorithms or mandate hybrid ones, people have done more damage to the PQ migration timeline than any adversary could have ever hoped for. If you care about securing the internet against CRQCs, please, stop talking about forbidding or requiring hybrids. On Wed, Aug 19, 2026 at 4:01 PM Ken Kubota <[email protected]> wrote: > "Extraordinary claims require extraordinary evidence, and I don't believe > you have provided it - however if we were to entertain your idea that the > IETF has indeed been captured by the NSA, then I would say - the IETF is > cooked." > > I wrote a concise email, anticipating swift censorship. > > > For further details, please see the following video: > > Verified Privacy VPN (vp.net): Daniel J. Bernstein (djb): The NSA, > the IETF, and the Fight to Weaken Your Encryption > https://youtu.be/qPhoJQtvgUo > > > More details are available at the webpages linked at > > https://mailarchive.ietf.org/arch/msg/ietf/FsbYnIjnGGX4Eek5DuUiZpc3cBI/ > > as well as my emails in the TLS and SSH archives at > https://mailarchive.ietf.org/arch/browse/tls/ > https://mailarchive.ietf.org/arch/browse/ssh/ > > > For example, I have demonstrated that virtually everyone strongly > recommends a hybrid approach: > https://mailarchive.ietf.org/arch/msg/ssh/Xx0yHcp2-z2A7oiELB-gxzgWs9k/ > > My original message detailing the involvement of eleven intelligence > service operatives from the NSA and other agencies was: > https://mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr6vgdjivHGj1mxCun3Rs/ > > > Nevertheless, in flagrant violation of fundamental security engineering > principles (including an RFC, see link above), a non-hybrid approach was > forced through. This decision was driven by the NSA, other agencies, and > affiliated companies voting en bloc, explicitly at odds with all leading > scientists -- including every professor (chair holder) I could identify. > The working group chairs now claim a 70% agreement while refusing to > provide the underlying data, despite numerous requests and without previous > serious objections being addressed. > Demands raised within the working group are instantly countered by > moderation (censorship) threats, and the Area Director -- a former NSA > lifetime employee -- has never attempted to address the problem, on the > contrary. > > > Kind regards, > > Ken Kubota > > ____________________________________________________ > > Ken Kubota > https://doi.org/10.4444/100 > > > > > Am 19.08.2026 um 21:42 schrieb Bron Gondwana <[email protected]>: > > > > I can tell you that I have never been employed by the NSA, nor any other > security service anywhere in the world. > > > > I have been moderating Dan Bernstein from the last-call list for > flagrant disregard for the IETF's norms, making personal attacks on > people's character and motivations, and continuing to grow the size of his > demands upon other people about how they treat his words and how they reply > to him (I too hate reading obvious AI slop. I don't put a link to the New > York Times about it on every email I send to thousands of people). > > > > I'm doing this under the authority dumped upon me back in 2020 under a > previous IESG when I was silly enough to accept responsibility for doing > so, and look forward to the day that the moderation team has a more > explicit set of rubrics I can apply rather than having to do so based on my > own good taste[CITATION NEEDED] and understanding of how jerks and/or rules > lawyers operate to filibuster the process when they have been found to be > in the rough. > > > > Extraordinary claims require extraordinary evidence, and I don't believe > you have provided it - however if we were to entertain your idea that the > IETF has indeed been captured by the NSA, then I would say - the IETF is > cooked. > > > > In such a case, you should join together with likeminded collaborators > and start your own standards organisation. Nothing is stopping you. You > could publish better specifications, not being captured by a state security > organisation, and over time persuade the world to use your specifications > instead. > > > > Nothing is forcing people to use the documents the IETF is publishing > other than their belief in the quality and serviceability of said documents. > > > > Regards, > > > > Bron. > > > > On Wed, Aug 19, 2026, at 15:06, Ken Kubota wrote: > >> > >> > >> Conflict of Interest: IETF and the NSA > >> > >> > >> The recent situation -- including the moderation at the SSH list by > Stephen Farrell [1] and the confirmation of a "PR action" by Security Area > Director Deb Cooley, a former lifetime employee of the NSA [2] -- leads me > to conclude without a doubt that the IETF has been fully captured by the > NSA, and that censorship of any dissent is the inevitable outcome. > >> > >> Neither Deb Cooley nor Stephen Farrell have ever responded to repeated > relevant questions concerning conflict of interest, and despite being > affected themselves, neither of them recused themselves. > >> > >> At no point did anyone from the IETF offer to discuss the issue of > conflict of interest openly. > >> > >> > >> This prompts me to point to Professor Bernstein's webpages, and > possibly my own: > >> > >> https://blog.cr.yp.to/20260814-update.html (2026.08.14: NSA and > IETF, part 9: An update. #pqcrypto #hybrids #nsa #ietf #procedures) > >> https://nsa.2026.action.cr.yp.to > >> https://blog.cr.yp.to > >> https://microblog.cr.yp.to > >> https://doi.org/10.4444/100 > >> > >> > >> Attached please find a clarification of my previous email. > >> > >> > >> Kind regards, > >> > >> Ken Kubota > >> > >> ____________________________________________________ > >> > >> Ken Kubota > >> https://doi.org/10.4444/100 > >> > >> > >> > >> [1] > https://mailarchive.ietf.org/arch/msg/ssh/2u4xoDmkRngOtgPe6tQ09P7d_W8/ > >> > >> [2] > https://mailarchive.ietf.org/arch/msg/ssh/GPVoqmoUEaYoynxfAOpl65-jZYA/ > >> > >> > >> > >> > Anfang der weitergeleiteten Nachricht: > >> > > >> > Von: Ken Kubota <[email protected]> > >> > Betreff: Aw: [Ssh] Complaint to SSHM chairs > >> > Datum: 19. August 2026 um 13:16:56 MESZ > >> > An: Stephen Farrell <[email protected]> > >> > Kopie: "[email protected]" <[email protected]>, Brian Berletic < > [email protected]> > >> > > >> > The following passage may cause misunderstandings, although the > quotes below provide all the factual information: > >> > > >> >> 2. Even worse, is it accurate that your company is indirectly > receiving money from Eric Schmidt (or his foundation)? > >> >> The company is known for supplying drones to Nazis. > >> >> Their business practices are so unethical that they are forced to > rebrand the company regularly. > >> > > >> > > >> > The company known for supplying drones to Nazis is Eric Schmidt's, > not Stephen Farrell's. > >> > My query is whether Stephen Farrell's company received or receives > money directly or indirectly from Eric Schmidt (including through one of > his -- Eric Schmidt's -- companies or foundations). > >> > This would constitute another conflict of interest, in my view, under > IETF regulations, besides accepting funds from the U.S. Department of State. > >> > > >> > > >> > Kind regards, > >> > > >> > Ken Kubota > >> > > >> > ____________________________________________________ > >> > > >> > Ken Kubota > >> > https://doi.org/10.4444/100 > >> > > >> > > >> > > >> > Reference: > https://mailarchive.ietf.org/arch/msg/ssh/I5o9rGgI_DMQAr5s0VR5b1XLP8I/ > >> > > >> > > >> > > >> >> Am 19.08.2026 um 01:29 schrieb Ken Kubota <[email protected]>: > >> >> > >> >> The issue of conflict of interest appears more widespread than > anticipated and also impacts the SSH Working Group. > >> >> > >> >> > >> >> 1. Is it accurate to assert that your company has received no less > than US$ 721,958 from the U.S. government, > >> >> and just within the last three years alone US$ 627,658 from the U.S. > "Department of State, Foreign Operations" > >> >> known for ongoing regime change attempts, constituting a blatant > violation of international law? > >> >> > >> >> > >> >> "Tolerant Networks was founded in April 2010 by Stephen Farrell and > Kerry Hartnett. The company" > >> >> "We are also working on ECH Encrypted ClientHello mechanism [...] > with funding from Open Technology Fund" > >> >> https://tolerantnetworks.com/ > >> >> > >> >> "Developing ECH for OpenSSL (DEfO)" > >> >> "This fine domain brought to you by Tolerant Networks Limited." > >> >> https://defo.ie/ > >> >> > >> >> "DEfO Sustainability > >> >> DEfO developed an implementation of the encrypted Client hello (ECH) > mechanism for OpenSSL." > >> >> "Funding to date > >> >> $721,958 > >> >> > >> >> 2023 > >> >> $234,725 > >> >> 24 months > >> >> (Free and Open Source Software Sustainability Fund) > >> >> 2023 > >> >> $392,933 > >> >> 24 months > >> >> (Internet Freedom Fund) > >> >> 2019 > >> >> $94,300 > >> >> 18 months" > >> >> > https://www.opentech.fund/projects-we-support/supported-projects/defo/ > >> >> > >> >> "Funding is appropriated for OTF through the annual Department of > State, Foreign Operations, and Related Programs appropriations and provided > to OTF via a grant agreement from USAGM. " > >> >> https://www.opentech.fund/about/about-our-funding/ > >> >> > >> >> "The Open Technology Fund was authorized by Congress in 2021 under > the National Defense Authorization Act." > >> >> https://www.opentech.fund/about/congressional-remit/ > >> >> > >> >> Brian Berletic: "Everyone talks about military industrial production > (including myself) but far too many ignore or underestimate the US' actual > superweapon, political capture through organization[s] like the NED, Open > Society, and USAID simply hidden better directly within the State > Department;" > >> >> https://t.me/brianlovethailand/4965 > >> >> > >> >> > >> >> 2. Even worse, is it accurate that your company is indirectly > receiving money from Eric Schmidt (or his foundation)? > >> >> The company is known for supplying drones to Nazis. > >> >> Their business practices are so unethical that they are forced to > rebrand the company regularly. > >> >> > >> >> > >> >> "Through the FOSS Sustainability Fund, DEfO will maintain and update > ECH code, push ECH to more TLS projects, support developers implementing > ECH, perform ongoing testing and monitoring, and flexibly repond to > emergent challenges." > >> >> > https://www.opentech.fund/projects-we-support/supported-projects/defo/ > >> >> > >> >> "For example, OTF’s FOSS Sustainability Fund is supported in part by > funding from Schmidt Futures’ Plaintext Group, Okta for Good, and the > Github Foundation." > >> >> https://www.opentech.fund/about/about-our-funding/ > >> >> > >> >> "US Gives Ukrainian Nazis AI-Guided Drones & Why These Are not > Game-Changers" > >> >> "France24 admits: "The US-designed Hornet was developed by the > American company Perennial Autonomy, which was founded and financed by > former Google CEO, Eric Schmidt. This drone is frequently used in US Army > training exercises. However, in July 2025, Perennial Autonomy – then called > Swift Beat – made a deal to supply Ukraine with drones," and that, "Elite > Ukrainian units like the Azov and Khartia Brigades have been posting images > of Hornet drones striking Russian supply convoys;"" > >> >> https://www.youtube.com/watch?v=UIiSUKlN07w > >> >> > >> >> Machine transcript: "And if you come down here, they talk about a > US-designed Hornet was developed by the American company Perennial > Autonomy, which was founded [and] finance[d] by former Google CEO Eric > Schmidt. Now, I did a video on this, and he constantly renamed the the > company. And they kind of admit that they did that on purpose so the > general public wouldn't be able to keep track of what it was doing." > >> >> https://youtu.be/UIiSUKlN07w?t=167 > >> >> > >> >> > >> >> 3. Is it accurate that the foundation your company received or > receives funds from is linked to the notorious Soros? > >> >> > >> >> > >> >> "Edin Omanovic > >> >> Open Society Foundations" > >> >> https://www.opentech.fund/otf-people/edin-omanovic/ > >> >> > >> >> "The Open Society Foundations, founded by George Soros, are the > world’s largest private funder" > >> >> https://www.opensocietyfoundations.org/who-we-are > >> >> > >> >> > >> >> > >> >>> Am 17.08.2026 um 02:58 schrieb Stephen Farrell <stephen.farrell= > [email protected]>: > >> >> > >> >>> Well, now you've been informed, so don't do it again eh? As a > >> >>> native (Irish:-) English speaker, your most recent message did > >> >>> clearly cross lines for me. > >> >>> > >> >>>> Could there be one that I am missing? My intention was to > >> >>>> clarify that he is acting on behalf of the NSA (e.g., the apparent > >> >>>> uniform voting patterns observed among NSA employees, or the weak > >> >>>> justification provided for a decision that contradicts virtually > all > >> >>>> existing recommendations). Would terms such as 'NSA official,' 'NSA > >> >>>> officer,' or 'NSA employees' be more appropriate? > >> >>> > >> >>> No. Addressing the substance of relevant messages is what's > >> >>> required, not throw-away affiliation-based slurs. I consider > >> >>> it should by now be entirely clear how you crossed that line. > >> >> > >> >> There are no slurs here. > >> >> The NSA's strategic documents are public now. > >> >> And Bernstein has detailed how the NSA is astroturfing the TLS > Working Group, with NSA people voting without ever having participated in > any debate. > >> >> > >> >> > >> >>> If you're not sure then contact the chairs off-list and we'll > >> >>> be happy to try help you understand that better. (But don't > >> >>> do that on-list please, or we'll quickly end up in moderation > >> >>> related territory.) > >> >> > >> >> The discussion can easily be finalized by reading the entry in the > Collins English Dictionary: > >> >> > >> >> "3. countable noun > >> >> An operative is someone who works for a government agency such as > the intelligence service. > >> >> [mainly US] > >> >> Naturally the CIA wants to protect its operatives. > >> >> Synonyms: spy, secret agent, double agent, secret service agent > More Synonyms of operative" > >> >> https://www.collinsdictionary.com/dictionary/english/operative > >> >> > >> >> The dictionary entry and IETF regulations render my choice of words > legitimate. > >> >> > >> >> You create the impression that you want to hide the obvious NSA > activity. > >> >> > >> >> Without any difficulty you could have provided an explanation or > rationale. > >> >> Repeatedly, you are not doing so. > >> >> > >> >> > >> >>>>> Meanwhile, DJB made a complaint. We (chairs) answered that, so if > >> >>>>> DJB wants to discuss that further, that seems fair. But other than > >> >>>>> that, I'd ask people to not jump in and engage on this thread. If > >> >>>>> some relevant point arises from any back > >> >>>> I completely agree with the substance of the complaint. Why should > >> >>>> others be excluded from a free and open debate, in line with IETF > >> >>>> principles? Also, the issues raised in the complaint pertain to all > >> >>>> members. > >> >>> > >> >>> It's not your complaint. If you have a complaint about issues with > >> >>> IETF processes on the SSH list then make that. As a chair, I can't > >> >> > >> >> I did complain: > >> >> > https://mailarchive.ietf.org/arch/msg/ssh/37o1nc4KxB7lz4Euekib8U95V2U/ > >> >> Your reaction was a censorship threat: > >> >> > https://mailarchive.ietf.org/arch/msg/ssh/QCnMkNJQUHFtxDl1fDvdM1pU8_c/ > >> >> > >> >> > >> >>> assume your perceived issues are identical to someone else's. And it > >> >>> is just not helpful to pile-on, whether supporting or disagreeing > >> >> > >> >> Reducing a free and open debate to a quantitative "pile-on" is > neither fair nor constructive. > >> >> It is preventing a free and open debate. > >> >> > >> >> > >> >>> with the complainant/chairs. > >> >>> > >> >>> Do be cognisant though, that this is the SSH list, not a venue > >> >>> for generic complaint about IETF process. > >> >> > >> >> IETF regulations (as outlined in the RFCs) clearly mandate that > conflicts be resolved within the WG first. > >> >> > >> >> > >> >>> And do please honour this chair's request to not further continue > >> >>> your on-list engagement in this thread. There are many more readers > >> >>> than writers involved, and you're just (IMO) pointlessly consuming > >> >>> readers time so far. > >> >> > >> >> As a chair, you should be neutral to a certain extent. > >> >> However, you are discouraging an open and free debate again, in > clear conflict with IETF regulations. > >> >> Any reader can decide whether to read the text in full or not. > >> >> Biased framing such as "you're just (IMO) pointlessly consuming > readers time" is inadequate (IMO). > >> >> > >> >> I have shown that virtually everybody strongly recommends a hybrid > approach: > >> >> > https://mailarchive.ietf.org/arch/msg/ssh/Xx0yHcp2-z2A7oiELB-gxzgWs9k/ > >> >> > >> >> Nevertheless you simply ignore all objections and continue to pursue > a non-hybrid approach. > >> >> > >> >> Bernstein has asked you "To clarify, when you say "the WG agreed"": > >> >> > https://mailarchive.ietf.org/arch/msg/ssh/Ru9KIoNbgOGgo910ANsYWSsirWs/ > >> >> > >> >> Until now I am not aware of any reasonable answer to this. > >> >> > >> >> > >> >>>>> Meanwhile, DJB made a complaint. We (chairs) answered that, so if > >> >>>>> DJB wants to discuss that further, that seems fair. But other than > >> >> > >> >> Excuse me, but Bernstein has made a precise, clear and detailed > critique, > >> >> while you have merely resorted to the technique of > counter-accusation, > >> >> without addressing the actual points of critique. > >> >> This can hardly be viewed as an "answer." > >> >> > >> >> If that is supposed to be the IETF conflict mechanism, the IETF is > lost. > >> >> > >> >> > >> >> Kind regards, > >> >> > >> >> Ken Kubota > >> >> > >> >> ____________________________________________________ > >> >> > >> >> Ken Kubota > >> >> https://doi.org/10.4444/100 > >> >> > >> >> _______________________________________________ > >> >> Ssh mailing list -- [email protected] > >> >> To unsubscribe send an email to [email protected] > >> > > >> > >> > > > > -- > > Bron Gondwana, CEO, Fastmail Pty Ltd / Fastmail US LLC > > [email protected] > > > > > >