[saag] Re: on derivative work rights statements in emails to Security Area mailing lists

Nico Williams <[email protected]> Sun, 23 Nov 2025 10:52:12 -0600
Newsgroups gmane.ietf.saag
Message-ID <aSM7vPRF+N7OwyaC@ubby>
On Sun, Nov 23, 2025 at 12:27:09PM -0300, Fernando Gont wrote:
> On 22/11/25 02:33, Nico Williams wrote:
> > Essentially that means that IETF consensus killing a WG work item is
> > extremely unlikely.
> > 
> > If you get a WG created, you'll get to publish its documents as RFCs
> > provided you follow the process.  I've worked on incepting two WGs, one
> > of which was somewhat controversial, so I know this from experience.
> 
> I'm not arguing you're wrong in this regard. However, that seems unlikely to
> help in raising the bar in terms of doc quality.

Let's put it in a different way: the IETF is an open society, or an open
society phenomenon, and open societies are particularly vulnerable to
attacks of the sort that DJB says are being mounted on the IETF _right
now_ (that the NSA is attacking the IETF, in a Dual_EC redux, which I
believe is in fact too likely a possibility to ignore).

Open societies seek to stay open, and therefore vulnerable.  The IETF in
particular is set up so that the NSA can walk right through its
processes and get what it wants with an utter minimum of dissimulation.

How do you defend the IETF in this situation?

I outlined two possible paths.  There might be others.  One thing for
sure is to keep up the pressure, but without getting oneself banned.  If
one door closes, try another.

> P.S.: I have seen docs killed by the IESG. The ongoing dicussion on the 6man
> wg list re eh-limits is a fresh datapoint.

The _IESG_ can kill docs, but I said it's the IETF that can't.  The IESG
is a very small group of people whose livelihoods might be negatively
impacted if they take certain positions (or so they might think).

Because they are a smaller group it's easier to convince them than the
IETF as a whole that some danger is real, but because of the potential/
perceived risk to their careers it can be harder.

Rather than spending energy on side issues let's focus on the one issue,
the core issue: that there are agencies that would try and maybe are
trying to get weak cryptography (or strong but back-doored cryptography)
into the mainstream with our blessing.  Any attempt to publish a do-not-
publish RFC on this matter will necessarily focus the energy onto that
issue.  If there are procedural bars in place, just publish another I-D
to address those.

Nico
-- 

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]