[saag] Re: on derivative work rights statements in emails to Security Area mailing lists

Fernando Gont <[email protected]> Sun, 23 Nov 2025 21:33:34 -0300
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
On 23/11/2025 13:52, Nico Williams wrote:
> On Sun, Nov 23, 2025 at 12:27:09PM -0300, Fernando Gont wrote:
>> On 22/11/25 02:33, Nico Williams wrote:
>>> Essentially that means that IETF consensus killing a WG work item is
>>> extremely unlikely.
>>>
>>> If you get a WG created, you'll get to publish its documents as RFCs
>>> provided you follow the process.  I've worked on incepting two WGs, one
>>> of which was somewhat controversial, so I know this from experience.
>>
>> I'm not arguing you're wrong in this regard. However, that seems unlikely to
>> help in raising the bar in terms of doc quality.
> 
> Let's put it in a different way: the IETF is an open society, or an open
> society phenomenon, and open societies are particularly vulnerable to
> attacks of the sort that DJB says are being mounted on the IETF _right
> now_ (that the NSA is attacking the IETF, in a Dual_EC redux, which I
> believe is in fact too likely a possibility to ignore).
> 
> Open societies seek to stay open, and therefore vulnerable.  The IETF in
> particular is set up so that the NSA can walk right through its
> processes and get what it wants with an utter minimum of dissimulation.
> 
> How do you defend the IETF in this situation?

Well, this is probably a topic for a separate thread. But let's just say 
that given where the meetings are held, and the fact that in order to 
participate in-person a fee is required, that helps any organization 
with a budget (whether Defense, or simply a commercial entity that want 
things in a specific direction) to bias the process. (yes, the IETF does 
better than other orgs, but that's not the point).

At least at some point, in-person participation determined NOMCOM 
eligibility, etc. which the in turn has an effect on IESG memebrs selection.


> I outlined two possible paths.  There might be others.  One thing for
> sure is to keep up the pressure, but without getting oneself banned.  If
> one door closes, try another.

I have only read one of djbs summaries of the issue at hand (literally, 
I got to seem some of the associated emails simply because I switched 
laptops and I had not yet configured filters for wg emails to go into 
their own mailboxes).



> Rather than spending energy on side issues let's focus on the one issue,
> the core issue: that there are agencies that would try and maybe are
> trying to get weak cryptography (or strong but back-doored cryptography)
> into the mainstream with our blessing.  Any attempt to publish a do-not-
> publish RFC on this matter will necessarily focus the energy onto that
> issue.  If there are procedural bars in place, just publish another I-D
> to address those.

Agreed. bu this seems to be at odds with "we should publish, since 
otherwise this would be pursued elsewhere". -- which is the point i was 
trying to make.

IOW, if this is a bad idea, the IETF shouldn't be publishing this.


P.S.: Interestingly enough, the ietf has published 
https://datatracker.ietf.org/doc/html/rfc7258

Thanks,
-- 
Fernando Gont
e-mail: [email protected]
PGP Fingerprint: 7F7F 686D 8AC9 3319 EEAD C1C8 D1D5 4B94 E301 6F01

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]