[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 20 26-07-08) (was Re: Re: Response to CoI Complaints)
Ken Kubota <[email protected]> Sun, 19 Jul 2026 12:15:40 +0200
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <[email protected]> |
"For the rocky parts of the discussion: the people that give you the name they use in real life and tell you that they work at the NSA are not the ones to worry about. That's fair dealing, and we try to be open to everyone, even when there are pretty serious philosophical disagreements."
Our stance must remain open, within the limits of core RFCs.
RFC 8890 ("The Internet is for End Users") [1] stands in direct conflict with the NSA's strategic goals of weakening internet encryption and planting back doors through clandestine operations [2]:
"The SIGINT Enabling Project actively engages the US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs."
"These design changes make the systems in question exploitable through SIGINT collection (e.g., Endpoint, MidPoint, etc.) with foreknowledge of the modification. To the consumer and other adversaries, however, the systems' security remains intact."
"Insert vulnerabilities into commercial encryption systems, IT systems, networks, and endpoint communications devices used by targets."
"Influence policies, standards and specification for commercial public key technologies."
"civilian pay and benefits"
Please note that the phrasing "consumer and other adversaries" implies that the "consumer" (in RFC terminology, the "end-user") is considered an adversary by the NSA.
Consequently, by prioritizing end-users, the IETF would also be considered an adversary by the NSA.
Kind regards,
Ken Kubota
____________________________________________________
Ken Kubota
https://doi.org/10.4444/100
[1] https://www.rfc-editor.org/rfc/rfc8890.html
[2] https://www.eff.org/files/2014/04/09/20130905-guard-sigint_enabling.pdf
> Am 18.07.2026 um 19:04 schrieb Rob Sayre <[email protected]>:
>
> On Sat, Jul 18, 2026 at 9:26 AM Jacob Appelbaum <[email protected] <mailto:[email protected]>> wrote:
>>
>>
>> Rob's (it was Rob, right?) suggestion appears to be a viable fallback.
>> The Independent Stream does not require IETF rough consensus, although
>> it is not an automatic bypass: the authors and ISE would have to pursue
>> it, and the IESG would still conduct the RFC 5742 conflict review
>> [0][1]. I note that the authors have largely not engaged in discussion.
>
> I think I reached for it, but it's not a novel thing. We do this all of the time.
>
> For the rocky parts of the discussion: the people that give you the name they use in real life and tell you that they work at the NSA are not the ones to worry about. That's fair dealing, and we try to be open to everyone, even when there are pretty serious philosophical disagreements.
>
> I prefer publishing via ISE, since people are going to use this spec. But Informational through the IETF is not something I would appeal. That is because I favor publishing without delay, and even wrote an RFC about it. :)
>
> thanks,
> Rob
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]