[TLS] Re: Response to CoI Complaints
John Mattsson <[email protected]> Thu, 16 Jul 2026 18:03:44 +0000
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <AS4PR07MB8825476C4E36D9E9854FCD4689C72@AS4PR07MB8825.eurprd07.prod.outlook.com> |
>It doesn't matter if Deb is a great neighbor, or how many colleagues send spooky and supportive e-mails. I think many people are concerned that Deb might simply decide to step away from the IETF and, rather than continue devoting so much unpaid time and effort to IETF work, choose to enjoy her retirement instead. The appropriate time to discuss whether Deb was suitable to become an AD was during the election process. >There is a reason that judges, regulators, and board members recuse themselves when a structural bias exists. Yet, this did not happen here. As the chair of a board, I often have to consider these kinds of issues. I do not think that having previously worked for the NSA, by itself, constitutes a conflict of interest. By contrast, participating in discussions about whether one's own research should be standardized seems like a much clearer potential conflict of interest. Do you think Bernstein should recuse himself or declare a conflict of interest every time X25519, ChaCha20, Poly1305, Classic McEliece, SLH-DSA, or NTRU Prime is discussed? Cheers, John Preuß Matttsson From: Andrew Lee <[email protected]> Date: Thursday, 16 July 2026 at 18:23 To: Scott Fluhrer (sfluhrer) <[email protected]> Cc: Tim Hollebeek <[email protected]>; Ryan Hurst <[email protected]>; TLS List <[email protected]> Subject: [TLS] Re: Response to CoI Complaints It's clear that Deb is a professional based on the countless responses in this thread!! Now that we have established this, I'd also like to point out that nobody asked, and further, this is quite off topic [1]. Furthermore, the issue isn't whether or not Deb Cooley is a person of proper moral turpitude. Instead, it's whether a 37-year NSA veteran can serve as a neutral arbiter in a process where NSA employees are flooding the list in support, most of whom are participating for their first time, where NSA's CNSA 2.0 framework requires the exact outcome the NSA desires from this process, and where NSA's Canadian partner stated on-list [2] that they are waiting for this RFC so they can recommend solo ML-KEM nationally. "This is not a conflict of interest," said nobody, ever. It doesn't matter if Deb is a great neighbor, or how many colleagues send spooky and supportive e-mails. There is a reason that judges, regulators, and board members recuse themselves when a structural bias exists. Yet, this did not happen here. Deb writes that "retired does not mean ... 'defected'." I agree. It also doesn't mean independent. Also, I want to reiterate something I mentioned to the Cypherpunks: The NSA recruits some of the best and brightest people. The kind of people you really want to have as a good ol' neighbor. These are the most principled, most talented people who are genuinely dedicated to public service. This is precisely why the NSA is so effective. The NSA is not an institution of villainry. It is a team of really good people, who are convinced by an institution they trust, to spy on their neighbors. DES, Dual EC, the SIGINT Enabling Project and its quarter-billion-dollar annual budget to "covertly influence" standards [3] was carried out by professionals with the utmost belief they were protecting their country. In other words, it is not Deb Cooley, the person, that concerns me. The issue is that a lifelong member of the NSA has utmost control over the consensus process of security decisions that affect billions of people. If we are to accept that 37 years at NSA creates no institutional bias on a question that directly serves NSA's stated mission, then the concept of conflict of interest has no meaning. Finally, Tim noted that it will be "impossible to find Area Directors" if structural concerns are raised. Please, allow me to fix this for you: it will be impossible to trust Area Directors if structural concerns cannot be raised. Another participant, Thomas, even went so far as to say that we may be "reaching the limits of the open society model." Yet, there was not a single response to the following: - Uri, an MS holder, called PhD holders and full professors "crypto-wannabes who are now flooding this list" - Paul accused participants of "consensus manipulation" while said subject was under moderation and unable to respond - etc. Meanwhile, Dr. Bernstein is still moderated for a footnote as Ted pointed out. If we are currently living in an Isekai where the heroes are, unpredictably, the most hated in society, then everything here makes sense. Sincerely, Andrew [1] https://mailarchive.ietf.org/arch/msg/tls/VowJMoJE2nfD83sY6KEoqKIIBgA/ [2] https://mailarchive.ietf.org/arch/msg/tls/uOeM5IRcYYjpNFlRyxEfo91q29c/ [3] https://www.eff.org/files/2014/04/09/20130905-guard-sigint_enabling.pdf On Jul 16, 2026, at 8:38 AM, Scott Fluhrer (sfluhrer) <[email protected]> wrote: I agree; in my experience, Deb has always acted honorably and professionally. Remember what it says in the Note Well: "Attack the idea. Don't attack the person" ________________________________ From: Tim Hollebeek <[email protected]> Sent: Thursday, July 16, 2026 10:49 AM To: Ryan Hurst <[email protected]>; Deb Cooley <[email protected]> Cc: TLS List <[email protected]> Subject: [TLS] Re: Response to CoI Complaints I completely agree with Ryan. These baseless accusations have no place at IETF. It's going to be impossible to find Area Directors in the future if this sort of behavior is deemed acceptable. Nobody should have to put up with these sorts of attacks. -Tim ________________________________ From: Ryan Hurst <[email protected]> Sent: Wednesday, July 15, 2026 6:38 PM To: Deb Cooley <[email protected]> Cc: TLS List <[email protected]> Subject: [TLS] Re: Response to CoI Complaints I have known Deb professionally and through the standards community for more than a decade. She is one of the most hardworking, principled, and public-service-minded people I have encountered in this field. You may disagree with Deb’s technical conclusions. You may disagree with how she has handled a particular matter as Security Area Director. Those disagreements are legitimate, and the IETF has well-established processes for raising them. What is not legitimate is turning those disagreements into insinuations about her integrity, loyalty, or professional history. Referring to someone who completed more than 37 years of public service and then retired as having “defected” is not criticism. It is a personal smear, and an especially ugly one. Deb has spent decades doing difficult, consequential, and often thankless work. In every interaction I have had with her, she has shown up prepared, engaged seriously with the substance, and acted according to her principles even when doing so was difficult or unpopular. Deb has earned better than this from the community she has served. Ryan Hurst On Wed, Jul 15, 2026 at 11:51 AM Deb Cooley <[email protected]<mailto:[email protected]>> wrote: For the record: I have been a Security Area Director since March 2024, that is 2 years and a couple of months. There have been previous inquiries into my ability to perform the duties of Security Area Director via the SSHM working group, and as part of complaints against the TLS chairs/AD. Those have been responded to by the IESG, the artifacts are below: https://mailarchive.ietf.org/arch/msg/ssh/7KRZCX_bvZWUOG50HqDg_KVT77c/<https://url.avanan.click/v2/r01/___https://mailarchive.ietf.org/arch/msg/ssh/7KRZCX_bvZWUOG50HqDg_KVT77c/___.YXAzOmRpZ2ljZXJ0OmE6bzpiYmE3MTIwOTRkMDZlNTEzNGFmM2IxMjVlY2U5ZTJiODo3OmVlNTY6YjJmM2YyM2U2MGMwOWRkMTYzY2Y1NDMwZDNmOGM4Yjg4ZjdjNThiYTZiMDQyMzg3NzM0MmEwMjFhMmFmOTUwNTpoOlQ6Rg> https://datatracker.ietf.org/group/iesg/appeals/<https://url.avanan.click/v2/r01/___https://datatracker.ietf.org/group/iesg/appeals/___.YXAzOmRpZ2ljZXJ0OmE6bzpiYmE3MTIwOTRkMDZlNTEzNGFmM2IxMjVlY2U5ZTJiODo3OmVmYTA6MWYwMTkwMTc2MmM5ZTAxZmU2YWE2OTE1ODFiMTRlZjA3ZWY0YTk4NjY3MjRjZjhlYjQxM2E1NGQwNmExODI5YzpoOlQ6Rg> (see artifacts 125/126, as well as 128/129) In addition to the artifacts above, I suggest that there might be people for whom I have worked with that could give an opinion on my work ethic and conduct for the last 2 plus years. The recourse for anyone who doesn’t believe this is a sufficient response is free to take a look at [RFC 8713, Section 7](https://www.rfc-editor.org/info/rfc8713/#section-7<https://url.avanan.click/v2/r01/___https://www.rfc-editor.org/info/rfc8713/%23section-7___.YXAzOmRpZ2ljZXJ0OmE6bzpiYmE3MTIwOTRkMDZlNTEzNGFmM2IxMjVlY2U5ZTJiODo3OmNiZGM6ZTg4ZTM3Mzk2MjAzZDJiMzU1OTJmZWIzNDg3MGNkN2E1ZTBiMTQ3YWJkZDQ0YTUwOWQ1NjE2MTJmMjQ0ZjljYzpoOlQ6Rg>). Just a couple of minor points: 1. Retirement means that I don't work for NSA anymore. I earn no salary. 2. Retired does not mean the same as 'defected'. 3. My bio is accurate see here: https://datatracker.ietf.org/person/Deb%20Cooley<https://url.avanan.click/v2/r01/___https://datatracker.ietf.org/person/Deb%20Cooley___.YXAzOmRpZ2ljZXJ0OmE6bzpiYmE3MTIwOTRkMDZlNTEzNGFmM2IxMjVlY2U5ZTJiODo3OjQ4Yjg6NDc4NTIzN2VjMTU4NGI5OGQxOGRjY2Y3ODBjMWY3Zjc1NGE4ODM2MTBmMWE5NzYyYTc1NTUzY2RjYWIxZjlmZDpoOlQ6Rg>. 37+ years of service in Cybersecurity which used to be Information Assurance, which used to be Information Security, which used to be COMSEC. 4. If you read RFC 9151, read all of it. Section 6 and 7 have MAY requirements which improve interoperability. Note that the draft was published in February 2021 when Adrian Farrel was the ISE. It was reviewed by a noteworthy set of reviewers including the late Jim Schaad. Deb Cooley Sec AD _______________________________________________ TLS mailing list -- [email protected]<mailto:[email protected]> To unsubscribe send an email to [email protected]<mailto:[email protected]> _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected] _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]