[TLS] Re: Question Regarding Consensus, IETF Procedures, and NSA Influence – Re: Scope of the IAB's appeal re sponse
John Mattsson <[email protected]> Wed, 15 Jul 2026 05:51:06 +0000
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <DB9PR07MB882126536A30E669A822274289F82@DB9PR07MB8821.eurprd07.prod.outlook.com> |
I find it somewhat ironic that your email simultaneously argues that the IETF process is failing while also complaining about an instance where the IETF process was clearly working, namely, the appeal process involving Wouters. To summarize your position, is it that whatever the IETF does, it is wrong? Your mail also raises an obvious question: do you apply the same criticism to ISO? Compared to the IETF, ISO is far less transparent, its cryptographic standards are paywalled, and its processes are much more heavily dominated by national government bodies. If government participation is, in itself, evidence that a standards body lacks legitimacy, then ISO would seem to present a much stronger case than the IETF. Cheers, John Preuß Mattsson From: Ken Kubota <[email protected]> Date: Wednesday, 15 July 2026 at 01:31 To: [email protected] <[email protected]> Cc: [email protected] <[email protected]>; IAB Chair <[email protected]>; TLS Chairs <[email protected]> Subject: [TLS] Question Regarding Consensus, IETF Procedures, and NSA Influence – Re: Scope of the IAB's appeal response Given the increasing number of media reports questioning both the validity of past procedures in this working group - including allegations of falsely claiming consensus - and the alleged compromise of the neutrality of current IETF procedures due to massive NSA influence, I seek clarification. I would also like to inquire whether Bernstein's claim regarding an unanswered email for nearly two months is accurate, as this situation creates the impression that established techniques are being employed to silence or block participants from exercising their rights. Furthermore, what measures were taken to halt such practices? When I mentioned the incident in this mailing list, no attempt was made to clarify the situation. Additionally, I have personally observed that when a prima facie obvious violation of an RFC by an Area Director (a former NSA lifetime employee) occurred, simple queries regarding this subsequent incident remained unanswered. In the broader context of your email below [1] regarding Daniel J. Bernstein's appeal [2], there have already been numerous media reports. For example, the leading German computer magazine featured an article titled "Is IETF standardization easy to hijack?" (machine translation) [3]. Another report alleges incorrect procedures (machine translation) [4]: "Problem 3: Retroactive reinterpretation of a failed WGLC The third issue is particularly serious: AD Wouters claimed in his message that the first WGLC of November 2025 was passed, albeit with the condition that a clarifying text favoring hybrid procedures in the general case be added. This portrayal stands in direct contradiction to the official Chairs' summary, which unambiguously noted the absence of consensus. This approach violates a fundamental principle of the IETF process: one cannot establish consensus for Measure X and subsequently reinterpret it as consensus for Measure Y without reconsulting the Working Group. The legitimacy of the entire process depends on decisions being communicated transparently and not being reinterpreted after the fact." With the massive presence of SIGINT operatives, namely NSA, GCHQ, and CSE in this working group [5], and the relevance of the results of this working group for internet security, the correctness and fairness of the outcomes are of paramount importance. Given the evident risks associated with non-hybrid approaches utilizing relatively experimental post-quantum algorithms (and the significant security vulnerability introduced by removing a hash function), experts would be justified in rejecting such measures; consequently, claiming a consensus is entirely unfounded. In my case, simple questions important for a fair procedure [6] remained unanswered [7] despite this reminder. Furthermore, there was never an attempt to explain obvious deficits, despite the active participation of both a current AD and a former AD in the WG mailing list: "I find it astonishing that Daniel J. Bernstein, a cryptographer, whose algorithms run half of the internet or more and who has an outstanding track record of pushing back against attempts to weaken cryptography, has received no response for nearly two months (14 Jun 2025 to 13 Aug 2025), even after providing, as requested, a permanent link [...]." [8] Under these circumstances, not only is the correctness of IETF procedures being questioned, but the legitimacy of the IETF itself is at risk, being perceived as an instrument of the NSA, notwithstanding the enormous scandals revealed by the Snowden documents. Kind regards, Ken Kubota ____________________________________________________ Ken Kubota https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdoi.org%2F10.4444%2F100&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687029894055%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=zJ1EHNgDGsus2vxwL%2FFF6WvG1xcY5qib9PznUdfEgpo%3D&reserved=0<https://doi.org/10.4444/100> [1] https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmailarchive.ietf.org%2Farch%2Fmsg%2Ftls%2F6wWaqTUY7eaXkkNldo9RTjXOwIY%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687029926698%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=BeSlJMRhR12r%2BrJlj4z%2FJHUI5nqEd471MbRD%2FMV8BqA%3D&reserved=0<https://mailarchive.ietf.org/arch/msg/tls/6wWaqTUY7eaXkkNldo9RTjXOwIY/> [2] https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fgroup%2Fiab%2Fappeals%2Fartifact%2F272&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687029946094%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=qVpJY5FJWVNoeX%2BooSfLCraLQW2NyXdk7y%2FfZGdFmIs%3D&reserved=0<https://datatracker.ietf.org/group/iab/appeals/artifact/272> [3] https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.heise.de%2Fselect%2Fct%2F2026%2F5%2F2533711343651986822&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687029964588%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=fDnlTWNddkzerqlGDcRVj5W46PPtvuOhzNDS5mpBtEQ%3D&reserved=0<https://www.heise.de/select/ct/2026/5/2533711343651986822> "Streit um TLS-Kryptografie Ist die IETF-Standardisierung leicht zu kapern?" [4] https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fopenxpki.com%2Fnews%2Fder-ueberstuerzte-weg-zu-post-quantum-tls-eine-kritische-analyse-des-ietf-standardisierungsprozesses.html&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687029986363%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=26nbgY79zQo1UjQVsaKMXLu5aWYpls3gzjyKD8lIWf4%3D&reserved=0<https://openxpki.com/news/der-ueberstuerzte-weg-zu-post-quantum-tls-eine-kritische-analyse-des-ietf-standardisierungsprozesses.html> "Der überstürzte Weg zu Post-Quantum-TLS: Eine Kritische Analyse des IETF-Standardisierungsprozesses […] Problem 3: Nachträgliche Umdeutung eines gescheiterten WGLC Besonders gravierend ist die dritte Problematik: AD Wouters behauptete in seiner Nachricht, der erste WGLC vom November 2025 habe bestanden – und zwar unter der Bedingung, dass ein klärender Text zur Bevorzugung hybrider Verfahren im Allgemeinfall hinzugefügt werde. Diese Darstellung widerspricht diametral der offiziellen Zusammenfassung der Chairs, die unmissverständlich das Fehlen von Konsens festgestellt hatten. Dieses Vorgehen verstößt gegen ein fundamentales Prinzip des IETF-Prozesses: Man kann keinen Konsens für Maßnahme X feststellen und diesen nachträglich in Konsens für Maßnahme Y umdeuten, ohne eine erneute Konsultation der WG. Die Legitimität des gesamten Verfahrens hängt davon ab, dass Entscheidungen transparent kommuniziert und nicht im Nachhinein reinterpretiert werden." [5] https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmailarchive.ietf.org%2Farch%2Fmsg%2Ftls%2FlnSPh3Wr6vgdjivHGj1mxCun3Rs%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687030004507%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=eprpvZ6VjOU8Q3%2Btf0SrmOqMKdnJCa9o44Wy5dfuEzo%3D&reserved=0<https://mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr6vgdjivHGj1mxCun3Rs/> "This would imply: - U.S. intelligence service: 6 - UK intelligence service: 3 - Canadian intelligence service: 2" [6] https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmailarchive.ietf.org%2Farch%2Fmsg%2Ftls%2FvFu5iq8gPQFByj4L0hkCEAJUR9I%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687030022177%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=El4RAwkgABebP2Pm7wl4tM54TQ5fCedSnCZ2XB8cWA0%3D&reserved=0<https://mailarchive.ietf.org/arch/msg/tls/vFu5iq8gPQFByj4L0hkCEAJUR9I/> [7] https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmailarchive.ietf.org%2Farch%2Fmsg%2Ftls%2FUDvPmpd0jIpcFkLgoZZSWlcH6Ok%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687030038933%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=dCmA0if2HwZRFpJRtKOYROLAMP0zcBZDiTkCeGtVmIE%3D&reserved=0<https://mailarchive.ietf.org/arch/msg/tls/UDvPmpd0jIpcFkLgoZZSWlcH6Ok/> "which you decided not to answer" [8] https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmailarchive.ietf.org%2Farch%2Fmsg%2Ftls%2FqijfEh8nZeMj0KqwRQDOBhITzfs%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687030056024%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=qSd3zNXHmO6AlDaeV%2FRPmSBepTQR0jiibUrawMW2%2BHg%3D&reserved=0<https://mailarchive.ietf.org/arch/msg/tls/qijfEh8nZeMj0KqwRQDOBhITzfs/> > Am 14.07.2026 um 13:52 schrieb IAB Chair <[email protected]>: > > TLS WG, > The IAB notes that its response to Daniel J. Bernstein’s 2026-04-24 appeal is being cited in ongoing working group discussion. To prevent that response from being read more broadly than intended, the IAB offers the clarification below. It takes no position on any other matter now before the WG, its chairs, or the IESG. > The IAB denied the appeal. It did not find that the chairs' determination of rough consensus to adopt fell outside the discretion that RFC 2418 affords them, nor that the responsible AD and the IESG acted outside their process role in declining to overturn that determination. > The relevant observation regarding the responsible AD was narrow. The IAB noted that the initial characterization of the adoption call by the responsible AD did not accurately describe the record, and that a more precise account followed. It was offered as encouragement to chairs and ADs to take care when summarizing participant responses. The observation concerned the accuracy of that account, not the intent behind it. It was not a finding that the responsible AD acted in bad faith, engaged in misconduct, or breached the IETF’s conduct norms. > The IAB has also seen its response read as reaching conclusions it did not state. The IAB did not determine that consensus to adopt was absent, nor did it overturn any consensus call. Its response should not be read as reaching conclusions on matters beyond the appeal, including the subsequent working group last call or the fact that a different Area Director became responsible for the working group. > Dhruv Dhody, > (as IAB Chair, for the IAB) > _______________________________________________ > TLS mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected] _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]