Re: Conflict of Interest: IETF and the NSA – Fwd: [Ssh] Complaint to SSHM chairs
Ken Kubota <[email protected]>
| Newsgroups | gmane.ietf.general,gmane.ietf.tls |
|---|---|
| Message-ID | <[email protected]> |
"I find this to be a sound technical document that neither endorses nor opposes the use of non-hybrid PQ, and that is the right approach for the IETF to take."
This point has been addressed many times.
The average person does not know this, which means that non-hybrid algorithms will be used.
Effectively, this is weakening encryption, and this is why publishing this draft is in the interest of the NSA, and why everybody honestly interested in preventing mass surveillance is strongly against it.
Professor Bernstein:
"There's this buried note in Section 6 saying "Recommended: N"!"
"A corporate purchasing manager will accurately understand the RFC as a standard, and won't even see, let alone care about, labels such as "Informational" or "Recommended: N"."
"NSA contractor Eric Rescorla has admitted that what's controversial here is the endorsement conveyed by the issuance of an RFC, even an "informational" non-"recommended" RFC: "I think it's clear that many regard the publication of an RFC by the TLS WG as a form of endorsement, even when Recommended=N [0]. In fact, this is precisely why the publication of some documents has become so controversial. ... [0] I don't think this position is entirely unreasonable given that the documents state on the face of them that they 'represent[s] the consensus of the IETF community.' ""
https://blog.cr.yp.to/20260702-standard.html (2026.07.02: A standard by any other name: How IETF evades responsibility for its actions. #standards #doublespeak)
Andreas Bartelt:
"Experience shows that unnecessarily weakened variants such as the TLS_AES_128_CCM_8_SHA256 cipher suite in TLS 1.3 will frequently show up in web server configurations. This cipher suite is almost always not intentionally enabled by the web server admins. IANA marking this cipher suite as "not recommended" doesn't really help in practice. I'd expect very similar problems with draft-ietf-tls-mlkem-08."
https://mailarchive.ietf.org/arch/msg/tls/PvC-J2Y0aOgG2K1CewZK5TItWX0/
Myself:
"It has already been pointed out earlier on this mailing list that RECOMMENDED = N is not a remedy, since the non-hybrid mechanism would still be implemented and used, effectively (!) weakening internet security by encouraging its deployment."
https://mailarchive.ietf.org/arch/msg/tls/zTe-KEEBzbJ5dqjmAxdy2VL45GQ/
I am willing to answer your other points also, although they have been thoroughly discussed at the places for which I have provided the links.
However, for doing so, I need more time.
If you are interested in open discussion, please help prevent censorship which seems to be in the making and supported by a certain group [e.g., 1, 2, 3, 4, 5].
However, chances are low, as Professor Bernstein points out:
2025.10.05: MODPOD: The collapse of IETF's protections for dissent. #ietf #objections #censorship #hybrids
https://blog.cr.yp.to/20251005-modpod.html
The problem of conflict of interest can be complex, particularly when financial flows are difficult to trace. Additionally, IETF mailing lists often focus on technical matters, which can sometimes lead to heated discussions where concerns about conflicts are mischaracterized as personal attacks.
Two examples:
1. Deb Cooley ("Retired Senior Cryptographic Vulnerability Analyst, National Security Agency Cybersecurity Directorate (NSA/CSD) with 37+ years of service in Dec 2023." [6]) repeatedly refuses to answer questions that would allow for fair and equal treatment:
"In my opinion, the warning email constitutes a violation of RFC 3934 Section 2, and therefore I asked questions 1, 2, 3, and 4 in the section addressed to you, which you decided not to answer except for the first part of question 1, even though they could be answered with a simple "yes" or "no" (or a short sentence).
This creates the impression that the rules are applied very restrictively to some people, while not being applied at all to others."
https://mailarchive.ietf.org/arch/msg/tls/UDvPmpd0jIpcFkLgoZZSWlcH6Ok/
2. John Mattsson is an employee of Ericsson [3]. It is worth noting that Ericsson has historical ties to the Swedish Wallenberg family. Discussions about the family's historical roles during World War II exist in historical literature. See:
The Duran: From Peace Nation to Battlefield, Sweden's NATO Transformation w/ Mats Nilsson
https://youtu.be/Tg84uEHYG2I
https://theduran.substack.com/p/from-peace-nation-to-battlefield
"Sweden has quietly ended 200 years of neutrality and is now officially designated as a NATO staging area against Russia, a transformation driven not by public debate but by the behind-the-scenes influence of the powerful Wallenberg banking dynasty and their stakes in Ericsson and Saab."
"00:05:13 The Wallenberg family: who they are and how they run Sweden
00:08:26 Wallenbergs during World War II: banking both sides
00:09:43 Nordic compass industrial alliance and Arctic militarization"
Of course, anybody with political experience would immediately see the conflict of interest and easily infer that Ericsson as part of the Wallenberg complex -- Saab produces military airplanes -- will support the NSA:
"They have to firmly align themselves with the Washington agenda in order to keep Ericsson and Saab profitable."
https://youtu.be/Tg84uEHYG2I&t=673
"Now, guess who was on the plane with the Social Democratic Minister heading off to meet Niinistö [president of Finland at that time] in Finland. Obviously, one of the Wallenbergs. They didn't even hide it. It was official, Wallenberg joined the trip to Helsingfors [Helsinki] to discuss the future of a 'possible' Swedish-Finnish membership in NATO. Of course, it was already decided by then, but the Social Democratic Party was allowed to go through the official democratic motions before it could be accepted policy. The voters were never asked."
https://youtu.be/Tg84uEHYG2I?t=765
For U.S. involvement, Professor Bernstein provides an excellent analysis at:
Section "What's likely to happen next?" [6]
2026.08.14: NSA and IETF, part 9: An update. #pqcrypto #hybrids #nsa #ietf #procedures
https://blog.cr.yp.to/20260814-update.html
Kind regards,
Ken Kubota
____________________________________________________
Ken Kubota
https://doi.org/10.4444/100
[1] Deb Cooley (37+ years NSA [6]): https://mailarchive.ietf.org/arch/msg/ssh/GPVoqmoUEaYoynxfAOpl65-jZYA/
[2] Stephen Farrell (co-founder of a company that received US$ 721,958 from the U.S. "Department of State, Foreign Operations"): https://mailarchive.ietf.org/arch/msg/ssh/FGgiLSFJytSY15oR8WuEsoEZzHE/
[3] John Mattsson (Ericsson / Swedish Wallenberg family): https://mailarchive.ietf.org/arch/msg/ssh/XuR9PwJlroGO88gLL8BOOrXk2qs/
[4] Damien Miller (?): https://mailarchive.ietf.org/arch/msg/ssh/QLCCJLXb9VsaCIOpsPyzRVv4YsA/
[5] Rich Salz (Akamai, sole provider of the Global Content Delivery Service to the Defense Information Systems Agency [7]): https://mailarchive.ietf.org/arch/msg/mod-discuss/pASkn8wiKb9DYOkBCENfRw97cjw/
[6] https://datatracker.ietf.org/person/Deb%20Cooley
"Deb Cooley
Pronouns: she/her
Photo of Deb Cooley
Deb Cooley
Retired Senior Cryptographic Vulnerability Analyst, National Security Agency Cybersecurity Directorate (NSA/CSD) with 37+ years of service in Dec 2023. Most of Deb’s career was spent as a security evaluator on many different technologies including IP encryptors, satellites, radios, and key management devices.
Previously, Special Government Expert for the Department of Homeland Security, Cybersecurity and Infrastructure Security Agency’s Cyber Security Division. Previously, acme working group chair."
[7] https://blog.cr.yp.to/20260814-update.html
"What's likely to happen next?
I'd like to think that IESG will look at the opposition statements from 75 people and say: okay, there's no consensus here, we have to reject this. I'd also like to think that IESG will grasp that this spec is contrary to the security goal in the TLS WG charter and doesn't serve any of the other goals in the charter, so it has to be rejected as a charter violation.
But the reality is that people tend to do what they're paid to do. So let's take a moment to look at the money flow.
I've previously posted quotes showing how NSA is pressuring its "vendors". For example, a Cisco employee wrote "that's what they're willing to buy. Hence, Cisco will implement it"; and an NSA employee wrote "Our interactions with vendors suggests that this won't be a problem in most cases". Here are some of the IESG members:
* Cisco employee Charles Eckel.
* Cisco employee Eric Vyncke.
* Cisco employee Ketan Talaulikar.
As another example, consider SEI. The SEI web page says "Sponsored by the Department of War, the SEI is a federally funded research and development center"; Congress's Office of Technology Assessment explained many years ago that FFRDCs are shell companies created by the U.S. government "to attract the best and the brightest people available using salary above the wage scale the federal government offers". SEI is hosted at a university, but it's a U.S. defense subsidiary, not an independent academic lab. Here are another two IESG members:
* SEI employee Roman Danyliw, IESG chair.
* SEI employee Christopher Inacio.
Let's try some more examples. Akamai is the sole provider of the Global Content Delivery Service to the Defense Information Systems Agency. Cloudflare and Nokia announced in March 2026 their participation in the "Missile Defense Agency Scalable Homeland Innovative Enterprise Layered Defense (SHIELD) indefinite-delivery/indefinite-quantity (IDIQ) contract with a ceiling of $151B". Each of these companies employs an IESG member:
* Akamai employee Mike Bishop.
* Cloudflare employee Tommy Jensen.
* Nokia employee Gunter Van de Velde.
Then there's NSA itself:
* NSA lifer Deb Cooley.
Cooley says she retired to join IESG in 2024. She was accurately listing NSA on a conflict-of-interest form after joining IESG. But then she switched to claiming that retirement removed the conflict of interest. No, it doesn't. That's the whole point of what are called "revolving door" prohibitions.
There are only 14 IESG members, and I've just listed 9 of them. So, okay, let's assume IESG makes up some excuse to approve the spec. What happens then?
There are procedures to appeal the decision by the WG chairs, first to NSA's Deb Cooley, then to the full IESG, then to another committee called the "Internet Architecture Board" (IAB), where defense-contractor employees (SEI employee Roman Danyliw, Cisco employee Suresh Krishnan, Cloudflare employee Mark Nottingham, Nokia employee Matthew Bocci, Google employee Warren Kumari, Comcast employee Jason Livingood, Zscaler employee Yaroslav Rosomakho) are again a majority.
There are also procedures to appeal the IESG decision, first to SEI's Roman Danyliw, then to the full IESG, then to IAB.
Anti-corruption organization Transparency International has a reference guide for procedures that organizations should set up to handle complaints. IETF doesn't follow any of that. IETF has no procedural constraints on how appeals are handled.
It also won't be surprising to see an RFC issued before appeals are resolved. Even without tons of money being thrown around, this would produce yet another incentive to deny the appeals, simply to avoid the paperwork of withdrawing an RFC.
There's one last level of appeal possible within the IETF procedures: complaining to the Board of Trustees of the Internet Society, IETF's parent organization, that IETF's procedures are "inadequate or insufficient to the protection of the rights of all parties in a fair and open Internet Standards Process". I already complained to ISOC in December 2025. ISOC said that the "timing and process" of handling the complaint would be discussed during ISOC's 25–26 July 2026 meeting and then the board would "designate someone to get in touch with you".
Maybe they'll designate board member Russ Housley. He's already familiar with what's going on:
* He has voted three times to issue this spec as an RFC. So he's familiar with the particular topic at hand.
* He was originally Air Force, and is now president of a small consulting firm called Akayla that has received $210000 in military contracts since 2023, as my regular readers might recall. So he's familiar with the influence of defense contracting.
* The six NSA employees who showed up in the latest round to vote for the spec—Mark Motley, Mike Jenkins, Morgan Stern, Nicholas Gajcowski, Peter Yee, and William Layton—include one, Peter Yee, who works not just for NSA but also for the same small firm Akayla. So Housley is familiar with NSA's interests.
* Sean Turner, one of the TLS WG chairs, is the "Treasurer, Secretary, and Security Officer" of Akayla (along with having various redacted affiliations). So Housley is familiar with the interests of the WG chairs. (Another TLS WG chair, the spec's author, is an employee of CIA-funded Sandbox AQ.)
* Housley served as IETF's Security Area Director 2003–2007, as IETF Chair 2007–2013, and as an IAB member 2007–2017. So he's familiar with how IETF works.
Sounds like he's the perfect man in the perfect position to make sure that the IETF procedures do what they're supposed to do. Let's see what happens!"
> Am 20.08.2026 um 00:22 schrieb Brian E Carpenter <[email protected]>:
>
> On 20-Aug-26 07:06, Ken Kubota wrote:
> ...
>> The recent situation -- including the moderation at the SSH list by Stephen Farrell [1] and the confirmation of a "PR action" by Security Area Director Deb Cooley, a former lifetime employee of the NSA
>
> The phrase "a former lifetime employee" is intrinsically self-contradictory. Ignoring that, a _former_ employee is not in a conflict of interest precisely because of the meaning of the word "former".
>
> Also, I see nothing in the declared funding source for https://tolerantnetworks.com/ to suggest an intrinsic conflict of interest. You would need to provide a lot more detail.
>
> On 20-Aug-26 09:00, Ken Kubota wrote:
>
>> a non-hybrid approach was forced through
>
> You are referring, I think, to a document clearly labelled "Intended status: Informational" which has not yet been approved for publication as an RFC. So it _has not_ been forced through and in any case, if published as an Informational RFC, it will not be normative. In fact it is carefully phrased (now, which was not true of earlier drafts) so that it does not argue for a non-hybrid algorithm, it simple explains how you could choose to use one if forced to do so.
>
> I find this to be a sound technical document that neither endorses nor opposes the use of non-hybrid PQ, and that is the right approach for the IETF to take. And precisely because of that, the question of conflict of interest seems irrelevant anyway.
>
> Regards
> Brian Carpenter
>
>