[TLS] Re: Question Regarding Consensus, IETF Procedures, and NSA Influence – Re: Scope of the IAB's appeal re sponse
Jacob Appelbaum <[email protected]> Wed, 15 Jul 2026 14:32:43 +0200
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <[email protected]> |
Hi John, On 7/15/26 07:51, John Mattsson wrote: > I find it somewhat ironic that your email simultaneously argues that > the IETF process is failing while also complaining about an instance > where the IETF process was clearly working, namely, the appeal > process involving Wouters. I do not read that record the same way. An appeal mechanism can exist and still leave serious process concerns unresolved. The question here is not whether every IETF mechanism is broken. The question is whether the specific concerns raised in this working group have been answered clearly, accurately, and systematically. The appearance of fairness also matters, especially when an insular group is interacting with the public or with the wider IETF community. > To summarize your position, is it that whatever the IETF does, it is > wrong? No. That is not anyone's expressed position, and I do not think it is a fair summary. One concern is clear, and has been raised by many people: when serious procedural and technical objections are raised, especially in a security-critical WG, they should be tracked, answered, and resolved in a way the community can inspect. Here is a concrete proposal: the datatracker should enable systematic tracking of issues raised, with an auditable record of who raised each issue, what the issue was, where it was discussed, when it was addressed, and why it was resolved or rejected. That would reduce confusion, support refinement of objections, and make it easier to detect some forms of process capture using ordinary process-tracing techniques. Would you support that kind of enhancement? > Your mail also raises an obvious question: do you apply the same > criticism to ISO? > > Compared to the IETF, ISO is far less transparent, its cryptographic > standards are paywalled, and its processes are much more heavily > dominated by national government bodies. I agree that ISO's paywalls are a serious problem, and I agree that the IETF is often more transparent. In many ways, the IETF is the better model. I trust that by starting with agreement, we are able to make some positive progress. But that does not answer Ken's questions. If anything, the comparison cuts both ways. My understanding is that ISO has more systematic issue tracking: comments, responses, and disposition histories are recorded in a way that makes accountability easier. That is exactly the kind of discipline I think would help here. Many people have raised this problem over many years. This is why I proposed a possible change to the datatracker. One of the problems in this discussion is that concerns are repeatedly described as already answered, already handled, or out of scope, without an authoritative list of issues, responses, and dispositions. NIST did not do that well in the ML-KEM process either, and the IETF should not inherit that weakness by reference. Certainly not by misrepresenting the situation! If you want to compare ISO and IETF on this point, I welcome that comparison. But it should be a concrete comparison of how objections are tracked, answered, and resolved. Since you raised ISO here, do you have relevant data about ML-KEM standardization or related cryptographic processes that supports your point? > If government participation is, in itself, evidence that a standards > body lacks legitimacy, then ISO would seem to present a much > stronger case than the IETF. Government participation by itself is not the issue, and I do not think that fairly characterizes Ken's point. Ken raised concerns about alleged false claims of consensus, unanswered emails, the handling of appeals and objections, the scale of SIGINT participation, and whether the WG is deferring to government preferences without adequately addressing technical objections. Those are different claims from "government participation is illegitimate." Government participants should participate as individuals like everyone else. But when government agencies with a documented history of cryptographic influence operations have a strong interest in an outcome, the WG should be especially careful to show its work. That means clear issue tracking, clear responses, and clear consensus calls. Do you dispute the substance of Ken's concern about NSA/GCHQ/CSE influence, or is your objection mainly to the word "massive"? If the issue is wording, that is easy to discuss. If the issue is substance, it would be helpful to address the specific claims. For example: if NSA strongly supports this draft, would NSA participants be willing to put their names on it? If not, the ISE path remains available for a document that does not claim TLS WG consensus. That would be cleaner than forcing WG consensus where serious technical and process concerns remain unresolved. Ken's earlier objection to the CNSA TLS profile was also not merely "NSA participated." It was that the Security Considerations did not explain why the ECC profile stopped at P-384 and omitted P-521, despite being a public NSA-authored TLS profile. One can disagree with Ken's conclusion, but the question of why 256-bit security is omitted is legitimate, especially when NSA recommends 256-bit security levels in other contexts. The same pattern appears here: concerns are dismissed, reframed, or declared answered without a systematic record showing that they were actually resolved. That is the process problem. You are an important participant in that process, John. I would welcome your help in making it more transparent and systematic. But treating Ken's questions as though they are themselves the problem does not help resolve the underlying issues. So, to your ISO comparison: yes, ISO has serious transparency problems, especially paywalls. But if ISO does a better job of systematically tracking and disposing of comments, they are better at transparency for ISO participants then the IETF and the IETF should learn from that rather than use ISO's other flaws as a distraction. Do you have a concrete ISO example of the same kind of issue happening there, with comparable records we can examine? If so, I would be interested in the comparison. I have left Ken's email below because it is worth reading in full. I would encourage everyone to focus on the substantive questions rather than dismissing or redirecting them, even inadvertently. I also want to say this carefully: given your Ericsson affiliation, the Athens Affair is relevant context when discussing lawful-intercept systems, backdoors, and institutional incentives [1][2][3][4]. I am not raising that as a personal accusation against you. I am raising it again because it is another example of why these concerns deserve systematic answers rather than informal dismissal. Is the Athens Affair somehow outside of your or Ericsson's threat model? It is not for other people on this list. Kind regards, Jacob Appelbaum [1] https://spectrum.ieee.org/the-athens-affair [2] https://www.theguardian.com/commentisfree/2015/sep/30/athens-affair- encryption-backdoors [3] https://theintercept.com/2015/09/28/death-athens-rogue-nsa-operation/ [4] https://blog.deepsec.net/deepsec-2015-talk-a-death-in-athens-the- inherent-vulnerability-of-lawful-intercept-programs-and-why-all- government-authorized-backdoors-are-very-dangerous-james-bamford/ > Cheers, John Preuß Mattsson > > From: Ken Kubota <[email protected]> Date: Wednesday, 15 July 2026 at > 01:31 To: [email protected] <[email protected]> Cc: [email protected] <[email protected]>; > IAB Chair <[email protected]>; TLS Chairs <tls- [email protected]> > Subject: [TLS] Question Regarding Consensus, IETF Procedures, and > NSA Influence – Re: Scope of the IAB's appeal response > > Given the increasing number of media reports questioning both the > validity of past procedures in this working group - including > allegations of falsely claiming consensus - and the alleged > compromise of the neutrality of current IETF procedures due to > massive NSA influence, I seek clarification. > > I would also like to inquire whether Bernstein's claim regarding an > unanswered email for nearly two months is accurate, as this > situation creates the impression that established techniques are > being employed to silence or block participants from exercising > their rights. Furthermore, what measures were taken to halt such > practices? > > When I mentioned the incident in this mailing list, no attempt was > made to clarify the situation. > > Additionally, I have personally observed that when a prima facie > obvious violation of an RFC by an Area Director (a former NSA > lifetime employee) occurred, simple queries regarding this > subsequent incident remained unanswered. > > > In the broader context of your email below [1] regarding Daniel J. > Bernstein's appeal [2], there have already been numerous media > reports. > > For example, the leading German computer magazine featured an > article titled "Is IETF standardization easy to hijack?" (machine > translation) [3]. > > > Another report alleges incorrect procedures (machine translation) > [4]: "Problem 3: Retroactive reinterpretation of a failed WGLC > > The third issue is particularly serious: AD Wouters claimed in his > message that the first WGLC of November 2025 was passed, albeit with > the condition that a clarifying text favoring hybrid procedures in > the general case be added. This portrayal stands in direct > contradiction to the official Chairs' summary, which unambiguously > noted the absence of consensus. > > This approach violates a fundamental principle of the IETF process: > one cannot establish consensus for Measure X and subsequently > reinterpret it as consensus for Measure Y without reconsulting the > Working Group. The legitimacy of the entire process depends on > decisions being communicated transparently and not being > reinterpreted after the fact." > > > With the massive presence of SIGINT operatives, namely NSA, GCHQ, > and CSE in this working group [5], and the relevance of the results > of this working group for internet security, the correctness and > fairness of the outcomes are of paramount importance. > > Given the evident risks associated with non-hybrid approaches > utilizing relatively experimental post-quantum algorithms (and the > significant security vulnerability introduced by removing a hash > function), experts would be justified in rejecting such measures; > consequently, claiming a consensus is entirely unfounded. > > In my case, simple questions important for a fair procedure [6] > remained unanswered [7] despite this reminder. > > Furthermore, there was never an attempt to explain obvious deficits, > despite the active participation of both a current AD and a former > AD in the WG mailing list: > > "I find it astonishing that Daniel J. Bernstein, a cryptographer, > whose algorithms run half of the internet or more and who has an > outstanding track record of pushing back against attempts to weaken > cryptography, has received no response for nearly two months (14 Jun > 2025 to 13 Aug 2025), even after providing, as requested, a > permanent link [...]." [8] > > > Under these circumstances, not only is the correctness of IETF > procedures being questioned, but the legitimacy of the IETF itself > is at risk, being perceived as an instrument of the NSA, > notwithstanding the enormous scandals revealed by the Snowden > documents. > > > Kind regards, > > Ken Kubota > > ____________________________________________________ > > Ken Kubota https://eur02.safelinks.protection.outlook.com/? > url=https%3A%2F%2Fdoi.org%2F10.4444%2F100&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687029894055%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=zJ1EHNgDGsus2vxwL%2FFF6WvG1xcY5qib9PznUdfEgpo%3D&reserved=0<https:// > doi.org/10.4444/100> > > > > [1] https://eur02.safelinks.protection.outlook.com/? > url=https%3A%2F%2Fmailarchive.ietf.org%2Farch%2Fmsg%2Ftls%2F6wWaqTUY7eaXkkNldo9RTjXOwIY%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687029926698%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=BeSlJMRhR12r%2BrJlj4z%2FJHUI5nqEd471MbRD%2FMV8BqA%3D&reserved=0<https:// > mailarchive.ietf.org/arch/msg/tls/6wWaqTUY7eaXkkNldo9RTjXOwIY/> > > [2] https://eur02.safelinks.protection.outlook.com/? > url=https%3A%2F%2Fdatatracker.ietf.org%2Fgroup%2Fiab%2Fappeals%2Fartifact%2F272&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687029946094%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=qVpJY5FJWVNoeX%2BooSfLCraLQW2NyXdk7y%2FfZGdFmIs%3D&reserved=0<https:// > datatracker.ietf.org/group/iab/appeals/artifact/272> > > [3] https://eur02.safelinks.protection.outlook.com/? > url=https%3A%2F%2Fwww.heise.de%2Fselect%2Fct%2F2026%2F5%2F2533711343651986822&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687029964588%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=fDnlTWNddkzerqlGDcRVj5W46PPtvuOhzNDS5mpBtEQ%3D&reserved=0<https:// > www.heise.de/select/ct/2026/5/2533711343651986822> "Streit um TLS- > Kryptografie > > Ist die IETF-Standardisierung leicht zu kapern?" > > [4] https://eur02.safelinks.protection.outlook.com/? > url=https%3A%2F%2Fopenxpki.com%2Fnews%2Fder-ueberstuerzte-weg-zu- > post-quantum-tls-eine-kritische-analyse-des-ietf- > standardisierungsprozesses.html&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687029986363%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=26nbgY79zQo1UjQVsaKMXLu5aWYpls3gzjyKD8lIWf4%3D&reserved=0<https:// > openxpki.com/news/der-ueberstuerzte-weg-zu-post-quantum-tls-eine- > kritische-analyse-des-ietf-standardisierungsprozesses.html> "Der > überstürzte Weg zu Post-Quantum-TLS: Eine Kritische Analyse des > IETF- Standardisierungsprozesses > > […] > > Problem 3: Nachträgliche Umdeutung eines gescheiterten WGLC > > Besonders gravierend ist die dritte Problematik: AD Wouters > behauptete in seiner Nachricht, der erste WGLC vom November 2025 > habe bestanden – und zwar unter der Bedingung, dass ein klärender > Text zur Bevorzugung hybrider Verfahren im Allgemeinfall hinzugefügt > werde. Diese Darstellung widerspricht diametral der offiziellen > Zusammenfassung der Chairs, die unmissverständlich das Fehlen von > Konsens festgestellt hatten. > > Dieses Vorgehen verstößt gegen ein fundamentales Prinzip des IETF- > Prozesses: Man kann keinen Konsens für Maßnahme X feststellen und > diesen nachträglich in Konsens für Maßnahme Y umdeuten, ohne eine > erneute Konsultation der WG. Die Legitimität des gesamten Verfahrens > hängt davon ab, dass Entscheidungen transparent kommuniziert und > nicht im Nachhinein reinterpretiert werden." > > [5] https://eur02.safelinks.protection.outlook.com/? > url=https%3A%2F%2Fmailarchive.ietf.org%2Farch%2Fmsg%2Ftls%2FlnSPh3Wr6vgdjivHGj1mxCun3Rs%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687030004507%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=eprpvZ6VjOU8Q3%2Btf0SrmOqMKdnJCa9o44Wy5dfuEzo%3D&reserved=0<https:// > mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr6vgdjivHGj1mxCun3Rs/> > "This would imply: - U.S. intelligence service: 6 - UK intelligence > service: 3 - Canadian intelligence service: 2" > > [6] https://eur02.safelinks.protection.outlook.com/? > url=https%3A%2F%2Fmailarchive.ietf.org%2Farch%2Fmsg%2Ftls%2FvFu5iq8gPQFByj4L0hkCEAJUR9I%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687030022177%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=El4RAwkgABebP2Pm7wl4tM54TQ5fCedSnCZ2XB8cWA0%3D&reserved=0<https:// > mailarchive.ietf.org/arch/msg/tls/vFu5iq8gPQFByj4L0hkCEAJUR9I/> > > [7] https://eur02.safelinks.protection.outlook.com/? > url=https%3A%2F%2Fmailarchive.ietf.org%2Farch%2Fmsg%2Ftls%2FUDvPmpd0jIpcFkLgoZZSWlcH6Ok%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687030038933%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=dCmA0if2HwZRFpJRtKOYROLAMP0zcBZDiTkCeGtVmIE%3D&reserved=0<https:// > mailarchive.ietf.org/arch/msg/tls/UDvPmpd0jIpcFkLgoZZSWlcH6Ok/> > "which you decided not to answer" > > [8] https://eur02.safelinks.protection.outlook.com/? > url=https%3A%2F%2Fmailarchive.ietf.org%2Farch%2Fmsg%2Ftls%2FqijfEh8nZeMj0KqwRQDOBhITzfs%2F&data=05%7C02%7Cjohn.mattsson%40ericsson.com%7C1d53ecbe02904d46d9dd08dee2000d77%7C92e84cebfbfd47abbe52080c6b87953f%7C0%7C0%7C639196687030056024%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=qSd3zNXHmO6AlDaeV%2FRPmSBepTQR0jiibUrawMW2%2BHg%3D&reserved=0<https:// > mailarchive.ietf.org/arch/msg/tls/qijfEh8nZeMj0KqwRQDOBhITzfs/> > > > >> Am 14.07.2026 um 13:52 schrieb IAB Chair <[email protected]>: >> >> TLS WG, The IAB notes that its response to Daniel J. Bernstein’s >> 2026-04-24 appeal is being cited in ongoing working group >> discussion. To prevent that response from being read more broadly >> than intended, the IAB offers the clarification below. It takes no >> position on any other matter now before the WG, its chairs, or the >> IESG. The IAB denied the appeal. It did not find that the chairs' >> determination of rough consensus to adopt fell outside the >> discretion that RFC 2418 affords them, nor that the responsible AD >> and the IESG acted outside their process role in declining to >> overturn that determination. The relevant observation regarding >> the responsible AD was narrow. The IAB noted that the initial >> characterization of the adoption call by the responsible AD did >> not accurately describe the record, and that a more precise >> account followed. It was offered as encouragement to chairs and >> ADs to take care when summarizing participant responses. The >> observation concerned the accuracy of that account, not the intent >> behind it. It was not a finding that the responsible AD acted in >> bad faith, engaged in misconduct, or breached the IETF’s conduct >> norms. The IAB has also seen its response read as reaching >> conclusions it did not state. The IAB did not determine that >> consensus to adopt was absent, nor did it overturn any consensus >> call. Its response should not be read as reaching conclusions on >> matters beyond the appeal, including the subsequent working group >> last call or the fact that a different Area Director became >> responsible for the working group. Dhruv Dhody, (as IAB Chair, for >> the IAB) _______________________________________________ TLS >> mailing list -- [email protected] To unsubscribe send an email to tls- >> [email protected] > > _______________________________________________ TLS mailing list -- > [email protected] To unsubscribe send an email to [email protected] > > > _______________________________________________ TLS mailing list -- > [email protected] To unsubscribe send an email to [email protected] _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]