[TLS] Re: Response to CoI Complaints

"Blumenthal, Uri - 0553 - MITLL" <[email protected]> Thu, 16 Jul 2026 17:01:35 +0000
Newsgroups gmane.ietf.tls
Message-ID <BN0P110MB141982694BCC4694E57D2F0A90C7A@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM>
I have a nagging suspicion that they attack the person exactly because they failed to successfully attack the idea.


My IETF experience goes beyond 30 years. I worked with Deb within the IETF context during the last several years — and can say nothing but good about her conduct, competence, and qualifications. (Unlike what I could say about some other people!)
--
V/R,
Uri


There are two ways to design a system. One is to make it so simple there are obviously no deficiencies.
The other is to make it so complex there are no obvious deficiencies.
C. A. R. Hoare




From: Scott Fluhrer (sfluhrer) <[email protected]>
Date: Thursday, July 16, 2026 at 11:40
To: Tim Hollebeek <[email protected]>; Ryan Hurst <[email protected]>; Deb Cooley <[email protected]>
Cc: TLS List <[email protected]>
Subject: [EXT] [TLS] Re: Response to CoI Complaints







I agree; in my experience, Deb has always acted honorably and professionally.


Remember what it says in the Note Well: "Attack the idea. Don't attack the person"


________________________________________
From: Tim Hollebeek <[email protected]>
Sent: Thursday, July 16, 2026 10:49 AM
To: Ryan Hurst <[email protected]>; Deb Cooley <[email protected]>
Cc: TLS List <[email protected]>
Subject: [TLS] Re: Response to CoI Complaints


I completely agree with Ryan. These baseless accusations have no place at IETF. It's going to be impossible to find Area Directors in the future if this sort of behavior is deemed acceptable. Nobody should have to put up with these sorts of attacks.


-Tim
________________________________________
From: Ryan Hurst <[email protected]>
Sent: Wednesday, July 15, 2026 6:38 PM
To: Deb Cooley <[email protected]>
Cc: TLS List <[email protected]>
Subject: [TLS] Re: Response to CoI Complaints


I have known Deb professionally and through the standards community for more than a decade. She is one of the most hardworking, principled, and public-service-minded people I have encountered in this field.
You may disagree with Deb’s technical conclusions. You may disagree with how she has handled a particular matter as Security Area Director. Those disagreements are legitimate, and the IETF has well-established processes for raising them.
What is not legitimate is turning those disagreements into insinuations about her integrity, loyalty, or professional history. Referring to someone who completed more than 37 years of public service and then retired as having “defected” is not criticism. It is a personal smear, and an especially ugly one.
Deb has spent decades doing difficult, consequential, and often thankless work. In every interaction I have had with her, she has shown up prepared, engaged seriously with the substance, and acted according to her principles even when doing so was difficult or unpopular.
Deb has earned better than this from the community she has served.
Ryan Hurst


On Wed, Jul 15, 2026 at 11:51 AM Deb Cooley <[email protected] <e531c63a-5db2-419a-8143-eb4ce39e8aa7>> wrote:


For the record: I have been a Security Area Director since March 2024, that is 2 years and a couple of months. 


There have been previous inquiries into my ability to perform the duties of Security Area Director via the SSHM working group, and as part of complaints against the TLS chairs/AD. Those have been responded to by the IESG, the artifacts are below: 


https://mailarchive.ietf.org/arch/msg/ssh/7KRZCX_bvZWUOG50HqDg_KVT77c/ <Protected by Avanan: https://mailarchive.ietf.org/arch/msg/ssh/7KRZCX_bvZWUOG50HqDg_KVT77c/>
https://datatracker.ietf.org/group/iesg/appeals/ <Protected by Avanan: https://datatracker.ietf.org/group/iesg/appeals/> (see artifacts 125/126, as well as 128/129)


In addition to the artifacts above, I suggest that there might be people for whom I have worked with that could give an opinion on my work ethic and conduct for the last 2 plus years.


The recourse for anyone who doesn’t believe this is a sufficient response is free to take a look at [RFC 8713, Section 7](https://www.rfc-editor.org/info/rfc8713/#section-7 <Protected by Avanan: https://www.rfc-editor.org/info/rfc8713/#section-7>).


Just a couple of minor points: 
1. Retirement means that I don't work for NSA anymore. I earn no salary. 
2. Retired does not mean the same as 'defected'. 
3. My bio is accurate see here: https://datatracker.ietf.org/person/Deb%20Cooley <Protected by Avanan: https://datatracker.ietf.org/person/Deb%20Cooley>. 37+ years of service in Cybersecurity which used to be Information Assurance, which used to be Information Security, which used to be COMSEC. 
4. If you read RFC 9151, read all of it. Section 6 and 7 have MAY requirements which improve interoperability. Note that the draft was published in February 2021 when Adrian Farrel was the ISE. It was reviewed by a noteworthy set of reviewers including the late Jim Schaad.




Deb Cooley 
Sec AD
_______________________________________________
TLS mailing list -- [email protected] <f81f6035-cd77-4e69-8ac2-0743508eda8a>
To unsubscribe send an email to [email protected] <9bbf2345-9ff0-4715-b130-54dfd6eb9dfe>

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/x-pkcs7-signature, 8 KB) - not displayed