[saag] Re: on derivative work rights statements in emails to Security Area mailing lists
Fernando Gont <[email protected]> Sun, 23 Nov 2025 21:33:34 -0300
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
On 23/11/2025 13:52, Nico Williams wrote: > On Sun, Nov 23, 2025 at 12:27:09PM -0300, Fernando Gont wrote: >> On 22/11/25 02:33, Nico Williams wrote: >>> Essentially that means that IETF consensus killing a WG work item is >>> extremely unlikely. >>> >>> If you get a WG created, you'll get to publish its documents as RFCs >>> provided you follow the process. I've worked on incepting two WGs, one >>> of which was somewhat controversial, so I know this from experience. >> >> I'm not arguing you're wrong in this regard. However, that seems unlikely to >> help in raising the bar in terms of doc quality. > > Let's put it in a different way: the IETF is an open society, or an open > society phenomenon, and open societies are particularly vulnerable to > attacks of the sort that DJB says are being mounted on the IETF _right > now_ (that the NSA is attacking the IETF, in a Dual_EC redux, which I > believe is in fact too likely a possibility to ignore). > > Open societies seek to stay open, and therefore vulnerable. The IETF in > particular is set up so that the NSA can walk right through its > processes and get what it wants with an utter minimum of dissimulation. > > How do you defend the IETF in this situation? Well, this is probably a topic for a separate thread. But let's just say that given where the meetings are held, and the fact that in order to participate in-person a fee is required, that helps any organization with a budget (whether Defense, or simply a commercial entity that want things in a specific direction) to bias the process. (yes, the IETF does better than other orgs, but that's not the point). At least at some point, in-person participation determined NOMCOM eligibility, etc. which the in turn has an effect on IESG memebrs selection. > I outlined two possible paths. There might be others. One thing for > sure is to keep up the pressure, but without getting oneself banned. If > one door closes, try another. I have only read one of djbs summaries of the issue at hand (literally, I got to seem some of the associated emails simply because I switched laptops and I had not yet configured filters for wg emails to go into their own mailboxes). > Rather than spending energy on side issues let's focus on the one issue, > the core issue: that there are agencies that would try and maybe are > trying to get weak cryptography (or strong but back-doored cryptography) > into the mainstream with our blessing. Any attempt to publish a do-not- > publish RFC on this matter will necessarily focus the energy onto that > issue. If there are procedural bars in place, just publish another I-D > to address those. Agreed. bu this seems to be at odds with "we should publish, since otherwise this would be pursued elsewhere". -- which is the point i was trying to make. IOW, if this is a bad idea, the IETF shouldn't be publishing this. P.S.: Interestingly enough, the ietf has published https://datatracker.ietf.org/doc/html/rfc7258 Thanks, -- Fernando Gont e-mail: [email protected] PGP Fingerprint: 7F7F 686D 8AC9 3319 EEAD C1C8 D1D5 4B94 E301 6F01 _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]