[TLS] Fwd: Warning about TLS mailing list behavior

Ken Kubota <[email protected]> Fri, 17 Jul 2026 03:38:32 +0200
Newsgroups gmane.ietf.tls
Message-ID <[email protected]>
Hi Joe,

To fully understand your criticism, please respond to the following points.

1. Please quote the exact formulations from the cited emails:
    https://mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr6vgdjivHGj1mxCun3Rs/
    https://mailarchive.ietf.org/arch/msg/tls/NhXrBcIlWhskI8uX0CllrTxEFuU/
that, in your opinion, "violate or are close to violating the IETF Code of Conduct."

2. Please explain why these instances constitute "personal attacks," and in particular, how I should be able to "intimidate other participants."
I hold no decision-making authority within the IETF (except as a member of the working group).
Consequently, I have no power to restrict anyone, and looking at the debate, there is no indication whatsoever that anyone has been intimidated.
What I did was cite facts and interpret them regarding a potential conflict of interest, which I consider a legitimate debate (see point 3).
It would also be helpful in this context to provide clarification as to whether the basis of an off-list warning shifted from "mischaracterization" to "personal attack," as described previously on this mailing list:
"1. Joseph Salowey issued me an off-list warning on July 6. He characterized my response to Paul Wouters as a "mischaracterization" of the IAB's findings.
2. I asked him to explain how a direct quote constitutes a mischaracterization. He could not.
3. He then pivoted the basis to "personal attack." I asked him to retract the warning as selectively applied and shared more clear counter examples. He did not respond." [1]
This creates the impression that "personal attack" is a standard accusation used to silence critics.
Making these emails public, if both parties agree, would help to mitigate repeated claims of biased behavior and to sharpen the criteria defining exactly what constitutes a "personal attack."
You might also take into account a participant's statement in your email to me: "Mentioning something that can be a conflict of interest doesnt violate code of conduct or close to. Harassment gets there but this was not it." [2]

3. In RFC 7282 (On Consensus and Humming in the IETF) Section 7 [3] titled "Five people for and one hundred people against might still be rough consensus" a conflict of interest is described, where one side "has a very elegant algorithm to address the issue, one which works especially well on their particular piece of hardware," "recruits one hundred people," "mostly people who work at the same company [...] and who never participated before," and engages in "vote stuffing."
The conflict of interest in this scenario is clearly of a financial nature, as the company would gain an advantage by selling their hardware ("same company," "especially well on their particular piece of hardware").
The underlying logic is that a conflict of interest revealed by specific behavior must be taken into consideration when determining whether a consensus exists.
I can immediately recall two NSA operatives and two employees of a French defense company who exhibited the exact same voting pattern without ever participating in the debate. One of the NSA operatives used a private account such that many readers do not immediately recognize him as an NSA official, and one of the two employees of the French defense company signed up solely for the purpose of voting.
For proper procedures at the IETF -- both regarding the question of whether a consensus exists as determined by the working group chair, and for any participant who wishes to challenge the decision of the working group chair according to IETF procedures -- the question of conflict of interest must be transparent, part of the debate, and properly documented.
Moreover, the question of whether a conflict of interest exists must remain open to discussion for every reader to determine.
The International Committee of Medical Journal Editors states this very clearly: "Although the presence of a relationship or activity does not always indicate a problematic influence on a paper’s content, perceptions of conflict may erode trust in science as much as actual conflicts of interest. Ultimately, readers must be able to make their own judgments regarding whether an author’s relationships and activities are pertinent to a paper’s content." [4]
Furthermore, the NSA is known for conducting clandestine operations [5]:
    "The SIGINT Enabling Project actively engages the US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs."
    "Insert vulnerabilities into commercial encryption systems, IT systems, networks, and endpoint communications devices used by targets."
With its multi-billion dollar budget, the NSA also generally has the means to practice social engineering, for example, by placing operatives at strategic positions in organizations or by funding covert actors who play their role in advancing the NSA's interests.
To make the situation even worse, companies from the communications or "defense" sector have a financial interest in receiving large-scale government orders, so they naturally tend to favor the NSA's position. Thus, while the question of conflict of interest is already, to some extent, a scientific matter -- as seen with the International Committee of Medical Journal Editors, where the reader (scientist) ultimately must be able to "make their own judgments" -- this becomes even more important in the context of a military intelligence service like the NSA, known for conducting clandestine operations and the power to also influence companies, e.g., by obtaining their support in standardization processes.
The question of conflict of interest must be part of the debate and discussed openly, including observations that may indicate conflicts of interest, which also applies to the behavior of participants, as seen in the RFC example cited above.
In particular, I find this argument disturbing: that a question regarding a conflict of interest "was already previously appealed and answered here by the IESG" [6] or "This matter is resolved as far as the IESG is concerned." [7] This eliminates any possibility for a meaningful discussion about the matter, although this matters for both scientific conduct in the field of cryptography -- where the NSA not only attacks cryptographic algorithms but also, as confirmed by its own leaked documents, conducts sabotage of cryptographic standardization processes -- as well as for the question of consensus.
The question of conflict of interest was assessed by a certain entity at a certain point in time to reach a certain decision.
Not only "[u]ltimately, readers must be able to make their own judgments" [4] about conflicts of interest, which requires an open debate, but also all ongoing developments must be included in it.
Simply relegating the question of conflict of interest to a certain entity's decision at a certain time (which in this case even only referred to an earlier decision by some other entity) is inconsistent with scientific practice (and also not with the example set out in the RFC).

I note that I require additional time to study IETF procedures and formulate my response.

Kind regards,

Ken Kubota

____________________________________________________

Ken Kubota
https://doi.org/10.4444/100



[1] https://mailarchive.ietf.org/arch/msg/tls/LvUiinuyMPCXTFMrbeYB0aa1Iw4/

[2] https://mailarchive.ietf.org/arch/msg/tls/P57ytYmUA6jxh_ehxR9_lMcQXQc/

[3] https://www.rfc-editor.org/rfc/rfc7282.html#section-7

[4] https://www.icmje.org/recommendations/browse/roles-and-responsibilities/author-responsibilities--conflicts-of-interest.html
"Individuals may disagree on whether an author’s relationships or activities represent conflicts. Although the presence of a relationship or activity does not always indicate a problematic influence on a paper’s content, perceptions of conflict may erode trust in science as much as actual conflicts of interest. Ultimately, readers must be able to make their own judgments regarding whether an author’s relationships and activities are pertinent to a paper’s content. These judgments require transparent disclosures. An author’s complete disclosure demonstrates a commitment to transparency and helps to maintain trust in the scientific process."

[5] https://www.eff.org/files/2014/04/09/20130905-guard-sigint_enabling.pdf

[6] https://mailarchive.ietf.org/arch/msg/tls/wahhT6eE39viKcIusKK4dTKzcIE/

[7] https://mailarchive.ietf.org/arch/msg/tls/GQ2cEosoHH9UyKp_9tIW15BW0Cw/



> Anfang der weitergeleiteten Nachricht:
> 
> Von: Ken Kubota <[email protected]>
> Betreff: [TLS] Fwd: Warning about TLS mailing list behavior
> Datum: 16. Juli 2026 um 01:20:24 MESZ
> An: [email protected]
> Kopie: [email protected], IAB Chair <[email protected]>, TLS Chairs <[email protected]>
> 
> For your information.
> 
> ____________________________________________________
> 
> Ken Kubota
> https://doi.org/10.4444/100
> 
> 
> 
>> Anfang der weitergeleiteten Nachricht:
>> 
>> Von: Joseph Salowey <[email protected]>
>> Betreff: Warning about TLS mailing list behavior
>> Datum: 15. Juli 2026 um 22:02:45 MESZ
>> An: [email protected]
>> 
>> HI Ken,
>> 
>> You have recently sent messages to the list that violate or are close to violating the IETF Code of Conduct in BCP 54 / RFC 7151. In particular we have identified the following issues:
>> 
>> You sent messages to the list that are personal attacks by accusing individuals of conflict of interest. Examples include [1] and [2] and additional messages on the list
>> 
>> This can be interpreted as an attempt to intimidate other participants. 
>> 
>> Please keep communication on the mailing list professional and civil. Consider this a private warning for inappropriate mailing list behavior; required by BCP 94 / RFC 3934.
>> 
>> Joe
>> TLS Working Group Co-Chair
>> 
>> [1] https://mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr6vgdjivHGj1mxCun3Rs/
>> [2] https://mailarchive.ietf.org/arch/msg/tls/NhXrBcIlWhskI8uX0CllrTxEFuU/
>> 
> 
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]