[TLS] Re: Improving the quality of the discussion on the TLS email list
Andrew Lee <[email protected]> Fri, 31 Jul 2026 11:50:32 -0700
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <[email protected]> |
--===============1782557684596848730== Content-Type: multipart/alternative; boundary="Apple-Mail=_5C409BA2-ED4F-4D06-8E4B-8A8286B8575F" --Apple-Mail=_5C409BA2-ED4F-4D06-8E4B-8A8286B8575F Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Dearest Filippo, Suggesting that Dr. Lange and Dr. Dunkelman somehow reverse engineer the = chairs' methodology is far from a serious response. Nobody should have to guess at blackbox processes when it comes to the = security of the billions of people on the internet. Further, an appeal = cannot be conducted when the process which produced the outcome is = unclear. I'd like to remind everyone what happened during this Solo ML-KEM rough = consensus determination exercise: 1. Not 1, not 2 but 3 WGLCs were conducted. 2. The AD issued statements about misrepresentation that occurred during = one of the WGLCs. 3. Cleary, messages were both filtered and moderated. 4. The hero who won the people of the world the right to write, research = and distribute cryptography was moderated from participating on the list = during the process due to a common footnote that was, simultaneously, = found and ignored from other participants. 5. This is already enough without having to mention the peculiarities = relating to the sudden involvement from intelligence agencies. Nobody is asking for an itemized vote list, Mr. Valsorda. However, I can = understand why the distinguished PhD cryptographers on this list are = concerned with the alarming conclusion to the rough consensus process... = since we didn't hum [1], nor did we use a formal count to arrive at an = outcome that contradicts what was suggested by nearly every discerning = PhD and professor on the list. So it's a pretty simple ask: 1. What counted as prior participation, 2. What counted as demonstrated domain expertise, AND 3. Were off list and moderated messages taken into consideration? If the process was legit, it should cost nothing to be transparent. = That said, the continued refusal to provide these details is actively = being written into history. At best, this process looks Mickey Mouse... at worst, infiltrated. Sincerely, Andrew [1] https://datatracker.ietf.org/doc/html/rfc7282 > On Jul 31, 2026, at 10:53=E2=80=AFAM, Filippo Valsorda = <[email protected]> wrote: >=20 > Hi Orr, >=20 > Emphasis added: >=20 >> Then, have you tried tallying support by =E2=80=9Cpre-existing WG = participants or people with demonstrated expertise=E2=80=9D using your = own methodology? Did you land at a result significantly different from = =E2=80=9Croughly 7/10=E2=80=9D? >=20 > I have high confidence that Tanja, or you if you want to help, can = give it a useful try. >=20 > 2026-07-31 19:10 GMT+02:00 Orr Dunkelman <[email protected] = <mailto:[email protected]>>: >> As the ADs did not publicly release the criteria relevant to what is = considered "prior involvement" (would participation in one discussion = before the ML-KEM sufficient to be considered in this set of voices?) = nor what are the "experienced people" they deemed to be worthy of being = heard (i.e., newcomers who are experienced), it is a bit impossible to = make the statistics you have asked Tanja to make. Actually, even putting = aside mailing issues, moderation problems, and assuming that indeed all = the votes were indeed public, no one but the ADs can make these = statistics. This is exactly what reasonable people asked for in this = mailing list (including people from academia, industry and government) - = to get these criteria publicly available. Hence, contacting IESG, IAB, = the UN, or even the local fire brigade, is useless until the ADs supply = this information.=20 >>=20 >> Furthermore, during the discussion I've pointed out that one of the = co-designers of MLKEM found the idea of standardizing only MLKEM to be = premature. I am sure that when assigning weights to participants, one of = the guys inventing the thing (and especially as this particular = individual has years of experience in industry, so this is not just a = theoretical computer scientist with no understanding of the real world), = should probably get a somewhat higher weight than even people who = participated in past TLS discussions. As the ADs did not report counting = this specific individual's "vote" (that says that the entire idea is = bad) it is unclear whether it was taken into account. Actually, I hope = to ask all the relevant co-designers when I meet them in future = conferences [relevant by my own personal secret criteria]. >>=20 >> Cheers, >>=20 >>=20 >>=20 >> On Fri, Jul 31, 2026 at 5:36=E2=80=AFPM Filippo Valsorda = <[email protected] <mailto:[email protected]>> wrote: >>=20 >> Excellent, sounds like you land at the same result as the chairs when = tallying support by all participants. That=E2=80=99s promising! >>=20 >> Then, have you tried tallying support by =E2=80=9Cpre-existing WG = participants or people with demonstrated expertise=E2=80=9D using your = own methodology? Did you land at a result significantly different from = =E2=80=9Croughly 7/10=E2=80=9D? >>=20 >> Assuming you=E2=80=99re not looking a priori for something to object = to, if you come to the same conclusion using your own methodology, I = don=E2=80=99t see what good demanding an itemized list would do. >>=20 >> If you do come to a significantly different result, you can share = your methodology in your appeal, and let the ADs, IESG, or IAB assess = it. >>=20 >> 2026-07-31 15:55 GMT+02:00 Tanja Lange <[email protected] = <mailto:[email protected]>>: >>> Dear Eliot, dear all, >>> I can tally the emails on list, which were about even in favor and = against. >>> The chairs announced that by some process of discarding or weighing = some votes >>> they reach 70% in favor. To quote this verbatim=20 >>> "However, if we look at pre-existing WG =20 >>> participants or people with demonstrated expertise, roughly 7/10 WG = =20 >>> participants favor advancing the document, which shows rough = consensus =20 >>> to move the document forward." >>> The requests I've seen, starting right after the chairs announced = their >>> decision that there was consensus in favor of the document, are = asking for >>> which input was discarded or counted higher or lower. I cannot do = the >>> "homework" of checking this because I don't know the mechanism used.=20= >>>=20 >>> Additionally, the email asking for responses was sent with >>> Reply-To: Joseph Salowey <[email protected] <mailto:[email protected]>> >>> so that replies would go to Joe's address and to the list only if = the sender >>> chooses to reply to all (or edits the header manually), so there = might be some >>> emails that didn't go to the list and which therefore I cannot count = when doing >>> my homework. >>>=20 >>> Finally, there are reports of messages not appearing on list despite = the >>> sender responding with the release code. We have seen some messages = containing >>> release codes appear on list (I hadn't seen that in any previous = discussion). >>> My understanding is that the chairs see those, and maybe that's = where the >>> chairs saw additional support, but I cannot count these in my = homework. >>>=20 >>> Hence, I would like to support the request for transparency of how = the 7/10 >>> (quoted above) was reached. >>>=20 >>> All the best >>> Tanja >>>=20 >>> On Fri, Jul 31, 2026 at 01:02:26PM +0200, Eliot Lear wrote: >>> > Hi, >>> >=20 >>> > On 31.07.2026 12:37, Ken Kubota wrote: >>> >=20 >>> > There have been repeated requests [1, 2] that the working = group chairs release the participant chart/list/table publicly that = supports the 70 % claim ("7/10 WG participants favor advancing the = document" [3]). >>> >=20 >>> > Unnecessary. All the information used by the chairs is publicly = available on >>> > this list. Do your own homework. Stop making work for others. >>> >=20 >>> >=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>> > _______________________________________________ >>> > TLS mailing list -- [email protected] <mailto:[email protected]> >>> > To unsubscribe send an email to [email protected] = <mailto:[email protected]> >>>=20 >>> _______________________________________________ >>> TLS mailing list -- [email protected] <mailto:[email protected]> >>> To unsubscribe send an email to [email protected] = <mailto:[email protected]> >>>=20 >>=20 >> _______________________________________________ >> TLS mailing list -- [email protected] <mailto:[email protected]> >> To unsubscribe send an email to [email protected] = <mailto:[email protected]> > _______________________________________________ > TLS mailing list -- [email protected] > To unsubscribe send an email to [email protected] --Apple-Mail=_5C409BA2-ED4F-4D06-8E4B-8A8286B8575F Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"content-type" content=3D"text/html; = charset=3Dutf-8"></head><body style=3D"overflow-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;"><div>Dearest = Filippo,</div><div><br></div><div>Suggesting that Dr. Lange and Dr. = Dunkelman somehow reverse engineer the chairs' methodology is far from a = serious response.</div><div><br></div><div>Nobody should have to guess = at blackbox processes when it comes to the security of the billions of = people on the internet. Further, an appeal cannot be conducted when the = process which produced the outcome is = unclear.</div><div><br></div><div>I'd like to remind everyone what = happened during this Solo ML-KEM rough consensus determination = exercise:</div><div><br></div><div>1. Not 1, not 2 but 3 WGLCs were = conducted.</div><div>2. The AD issued statements about misrepresentation = that occurred during one of the WGLCs.</div><div>3. Cleary, messages = were both filtered and moderated.</div><div>4. The hero who won the = people of the world the right to write, research and distribute = cryptography was moderated from participating on the list during the = process due to a common footnote that was, simultaneously, found and = ignored from other participants.</div><div>5. This is already enough = without having to mention the peculiarities relating to the sudden = involvement from intelligence agencies.</div><div><br></div><div>Nobody = is asking for an itemized vote list, Mr. Valsorda. However, I can = understand why the distinguished PhD cryptographers on this list are = concerned with the alarming conclusion to the rough consensus process... = since we didn't hum [1], nor did we use a formal count to arrive at an = outcome that contradicts what was suggested by nearly every discerning = PhD and professor on the list.</div><div><br></div><div>So it's a pretty = simple ask:</div><div><br></div><div>1. What counted as prior = participation,</div><div>2. What counted as demonstrated domain = expertise, AND</div><div>3. Were off list and moderated messages taken = into consideration?</div><div><br></div><div>If the process was legit, = it should cost nothing to be transparent. That said, the continued = refusal to provide these details is actively being written into = history.</div><div><br></div><div>At best, this process looks Mickey = Mouse... at worst, = infiltrated.</div><div><br></div><div>Sincerely,</div><div>Andrew</div><di= v><br></div><div>[1] = https://datatracker.ietf.org/doc/html/rfc7282</div><div><br><blockquote = type=3D"cite"><div>On Jul 31, 2026, at 10:53=E2=80=AFAM, Filippo = Valsorda <[email protected]> wrote:</div><br = class=3D"Apple-interchange-newline"><div><title></title><div><div>Hi = Orr,</div><div><br></div><div>Emphasis = added:</div><div><br></div><blockquote type=3D"cite"><div>Then, have you = tried tallying support by =E2=80=9Cpre-existing WG participants or = people with demonstrated expertise=E2=80=9D <b>using your own = methodology</b>? Did you land at a result significantly different from = =E2=80=9Croughly 7/10=E2=80=9D?<br></div></blockquote><div><br></div><div>= I have high confidence that Tanja, or you if you want to help, can give = it a useful try.</div><div><br></div><div>2026-07-31 19:10 GMT+02:00 Orr = Dunkelman <<a = href=3D"mailto:[email protected]">[email protected]</a>>:</div><blo= ckquote type=3D"cite" id=3D"qt" style=3D""><div dir=3D"ltr"><div>As the = ADs did not publicly release the criteria relevant to what is considered = "prior involvement" (would participation in one discussion before the = ML-KEM sufficient to be considered in this set of voices?) nor what = are the "experienced people" they deemed to be worthy of being heard = (i.e., newcomers who are experienced), it is a bit impossible to make = the statistics you have asked Tanja to make. Actually, even putting = aside mailing issues, moderation problems, and assuming that indeed all = the votes were indeed public, no one but the ADs can make these = statistics. This is exactly what reasonable people asked for in this = mailing list (including people from academia, industry and government) - = to get these criteria publicly available. Hence, contacting IESG, IAB, = the UN, or even the local fire brigade, is useless until the ADs supply = this information. </div><div><br></div><div>Furthermore, during the = discussion I've pointed out that one of the co-designers of = MLKEM found the idea of standardizing only MLKEM to be premature. I = am sure that when assigning weights to participants, one of the guys = inventing the thing (and especially as this particular individual has = years of experience in industry, so this is not just a theoretical = computer scientist with no understanding of the real world), should = probably get a somewhat higher weight than even people who participated = in past TLS discussions. As the ADs did not report counting this = specific individual's "vote" (that says that the entire idea is bad) it = is unclear whether it was taken into account. Actually, I hope to ask = all the relevant co-designers when I meet them in future conferences = [relevant by my own personal secret = criteria].</div><div><br></div><div>Cheers,</div><div><br></div><div><br><= /div></div><div><br></div><div class=3D"qt-gmail_quote = qt-gmail_quote_container"><div dir=3D"ltr" class=3D"qt-gmail_attr">On = Fri, Jul 31, 2026 at 5:36=E2=80=AFPM Filippo Valsorda <<a = href=3D"mailto:[email protected]">[email protected]</a>> = wrote:</div><blockquote class=3D"qt-gmail_quote" = style=3D"margin-top:0px;margin-right:0px;margin-bottom:0px;margin-left:0.8= ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204= , 204, = 204);padding-left:1ex;"><div><u></u><br></div><div><div>Excellent, = sounds like you land at the same result as the chairs when tallying = support by all participants. That=E2=80=99s = promising!</div><div><br></div><div>Then, have you tried tallying = support by =E2=80=9Cpre-existing WG participants or people with = demonstrated expertise=E2=80=9D using your own methodology? Did you land = at a result significantly different from =E2=80=9Croughly = 7/10=E2=80=9D?</div><div><br></div><div>Assuming you=E2=80=99re not = looking a priori for something to object to, if you come to the same = conclusion using your own methodology, I don=E2=80=99t see what good = demanding an itemized list would do.</div><div><br></div><div>If you do = come to a significantly different result, you can share your methodology = in your appeal, and let the ADs, IESG, or IAB assess = it.</div><div><br></div><div>2026-07-31 15:55 GMT+02:00 Tanja Lange = <<a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a>>:</div><blockquote = type=3D"cite" id=3D"qt-m_-6319647677144171176qt"><div>Dear Eliot, dear = all,</div><div>I can tally the emails on list, which were about even in = favor and against.</div><div>The chairs announced that by some process = of discarding or weighing some votes</div><div>they reach 70% in favor. = To quote this verbatim </div><div>"However, if we look at = pre-existing = WG = </= div><div>participants or people with demonstrated expertise, roughly = 7/10 = WG = </div><d= iv>participants favor advancing the document, which shows rough = consensus  = ; </div><div>to = move the document forward."</div><div>The requests I've seen, starting = right after the chairs announced their</div><div>decision that there was = consensus in favor of the document, are asking for</div><div>which input = was discarded or counted higher or lower. I cannot do = the</div><div>"homework" of checking this because I don't know the = mechanism used. </div><div><br></div><div>Additionally, the email = asking for responses was sent with</div><div>Reply-To: Joseph Salowey = <<a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a>></div><div>so that replies = would go to Joe's address and to the list only if the = sender</div><div>chooses to reply to all (or edits the header manually), = so there might be some</div><div>emails that didn't go to the list and = which therefore I cannot count when doing</div><div>my = homework.</div><div><br></div><div>Finally, there are reports of = messages not appearing on list despite the</div><div>sender responding = with the release code. We have seen some messages = containing</div><div>release codes appear on list (I hadn't seen that in = any previous discussion).</div><div>My understanding is that the chairs = see those, and maybe that's where the</div><div>chairs saw additional = support, but I cannot count these in my = homework.</div><div><br></div><div>Hence, I would like to support the = request for transparency of how the 7/10</div><div>(quoted above) was = reached.</div><div><br></div><div>All the = best</div><div>Tanja</div><div><br></div><div>On Fri, Jul 31, 2026 at = 01:02:26PM +0200, Eliot Lear wrote:</div><div>> = Hi,</div><div>> </div><div>> On 31.07.2026 12:37, Ken Kubota = wrote:</div><div>> </div><div>> There = have been repeated requests [1, 2] that the working group chairs release = the participant chart/list/table publicly that supports the 70 % claim = ("7/10 WG participants favor advancing the document" = [3]).</div><div>> </div><div>> Unnecessary. All the = information used by the chairs is publicly available on</div><div>> = this list. Do your own homework. Stop making work for = others.</div><div>> </div><div>> </div><div><br></div><div= ><br></div><div><br></div><div><br></div><div><br></div><div><br></div><di= v>> _______________________________________________</div><div>> = TLS mailing list -- <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a></div><div>> To unsubscribe send an = email to <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a></div><div><br></div><div>________= _______________________________________</div><div>TLS mailing list = -- <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a></div><div>To unsubscribe send an = email to <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a></div><div><br></div></blockquote>= <div><br></div></div><div>_______________________________________________<= /div><div> TLS mailing list -- <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a></div><div> To unsubscribe send an = email to <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a></div></blockquote></div></blockqu= ote><div><br></div></div>_______________________________________________<b= r>TLS mailing list -- [email protected]<br>To unsubscribe send an email to = [email protected]<br></div></blockquote></div><br></body></html>= --Apple-Mail=_5C409BA2-ED4F-4D06-8E4B-8A8286B8575F-- --===============1782557684596848730== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0 bHMtbGVhdmVAaWV0Zi5vcmcK --===============1782557684596848730==--