[saag] Re: on derivative work rights statements in emails to Security Area mailing lists

Nico Williams <[email protected]> Mon, 24 Nov 2025 15:49:32 -0600
Newsgroups gmane.ietf.saag
Message-ID <aSTS7IRWIavGPD2A@ubby>
On Sun, Nov 23, 2025 at 09:33:34PM -0300, Fernando Gont wrote:
> On 23/11/2025 13:52, Nico Williams wrote:
> > How do you defend the IETF in this situation?
> 
> Well, this is probably a topic for a separate thread. But let's just say
> [...]
> 
> At least at some point, in-person participation determined NOMCOM
> eligibility, etc. which the in turn has an effect on IESG memebrs selection.

Yes.  The IETF is costly to participate in (because participants have to
dedicate a great deal of labor to it, and because of the travel costs,
and if you want to be in the leadership you must attend all meetings,
and if you're a WG chair and you have in-person interims you have to
attend those too, and if you want to be in the NomCom you have to attend
many (most?) meetings over some time period, and being an AD is a
full-time job).  Ergo very few people are eligible to be in the
leadership.  But also because mailing list participation is open it's
also possible to have so many participants from one vendor (or other
org) that you can drive consensus in some/many cases.  I.e., the IETF is
vulnerable to well-funded attempts to steer it.

That's what I was getting at.

> > Rather than spending energy on side issues let's focus on the one issue,
> > the core issue: [...]
> 
> Agreed. bu this seems to be at odds with "we should publish, since otherwise
> this would be pursued elsewhere". -- which is the point i was trying to
> make.

Sure, I suggested something like that in the process of defending the WG
chair's decision.  Honestly I'm not entirely sure that the decision was
defensible because I have never been a WG chair and never had WG chair
training.  But we don't have to get to defending or attacking that
decision: the IESG (or was it only the AD?) has said that the decision
was legitimate and rejected the appeal.  We can keep arguing over that
all you want, but if we're going to make progress we should accept that
that door is closed and move on to the next door.

> IOW, if this is a bad idea, the IETF shouldn't be publishing this.

I agree, but that decision has been made, so now we get to argue about
RFC track, MTI, etc.

I propose someone submit an I-D titled something like "Five-year
Moratorium on Non-Hybrid Post-Quantum Public Key Cryptosystems".

Nico
-- 

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]