Given the increasing number of media reports questioning both the validity of
past procedures in this working group - including allegations of falsely
claiming consensus - and the alleged compromise of the neutrality of current
IETF procedures due to massive NSA influence, I seek clarification.
I would also like to inquire whether Bernstein's claim regarding an unanswered
email for nearly two months is accurate, as this situation creates the
impression that established techniques are being employed to silence or block
participants from exercising their rights. Furthermore, what measures were
taken to halt such practices?
When I mentioned the incident in this mailing list, no attempt was made to
clarify the situation.
Additionally, I have personally observed that when a prima facie obvious
violation of an RFC by an Area Director (a former NSA lifetime employee)
occurred, simple queries regarding this subsequent incident remained unanswered.
In the broader context of your email below [1] regarding Daniel J. Bernstein's
appeal [2], there have already been numerous media reports.
For example, the leading German computer magazine featured an article titled
"Is IETF standardization easy to hijack?" (machine translation) [3].
Another report alleges incorrect procedures (machine translation) [4]:
"Problem 3: Retroactive reinterpretation of a failed WGLC
The third issue is particularly serious: AD Wouters claimed in his message that
the first WGLC of November 2025 was passed, albeit with the condition that a
clarifying text favoring hybrid procedures in the general case be added. This
portrayal stands in direct contradiction to the official Chairs' summary, which
unambiguously noted the absence of consensus.
This approach violates a fundamental principle of the IETF process: one cannot
establish consensus for Measure X and subsequently reinterpret it as consensus
for Measure Y without reconsulting the Working Group. The legitimacy of the
entire process depends on decisions being communicated transparently and not
being reinterpreted after the fact."
With the massive presence of SIGINT operatives, namely NSA, GCHQ, and CSE in
this working group [5], and the relevance of the results of this working group
for internet security, the correctness and fairness of the outcomes are of
paramount importance.
Given the evident risks associated with non-hybrid approaches utilizing
relatively experimental post-quantum algorithms (and the significant security
vulnerability introduced by removing a hash function), experts would be
justified in rejecting such measures; consequently, claiming a consensus is
entirely unfounded.
In my case, simple questions important for a fair procedure [6] remained
unanswered [7] despite this reminder.
Furthermore, there was never an attempt to explain obvious deficits, despite
the active participation of both a current AD and a former AD in the WG mailing
list:
"I find it astonishing that Daniel J. Bernstein, a cryptographer, whose
algorithms run half of the internet or more and who has an outstanding track
record of pushing back against attempts to weaken cryptography, has received no
response for nearly two months (14 Jun 2025 to 13 Aug 2025), even after
providing, as requested, a permanent link [...]." [8]
Under these circumstances, not only is the correctness of IETF procedures being
questioned, but the legitimacy of the IETF itself is at risk, being perceived
as an instrument of the NSA, notwithstanding the enormous scandals revealed by
the Snowden documents.
Kind regards,
Ken Kubota
____________________________________________________
Ken Kubota
https://doi.org/10.4444/100
[1] https://mailarchive.ietf.org/arch/msg/tls/6wWaqTUY7eaXkkNldo9RTjXOwIY/
[2] https://datatracker.ietf.org/group/iab/appeals/artifact/272
[3] https://www.heise.de/select/ct/2026/5/2533711343651986822
"Streit um TLS-Kryptografie
Ist die IETF-Standardisierung leicht zu kapern?"
[4]
https://openxpki.com/news/der-ueberstuerzte-weg-zu-post-quantum-tls-eine-kritische-analyse-des-ietf-standardisierungsprozesses.html
"Der überstürzte Weg zu Post-Quantum-TLS: Eine Kritische Analyse des
IETF-Standardisierungsprozesses
[…]
Problem 3: Nachträgliche Umdeutung eines gescheiterten WGLC
Besonders gravierend ist die dritte Problematik: AD Wouters behauptete in
seiner Nachricht, der erste WGLC vom November 2025 habe bestanden – und zwar
unter der Bedingung, dass ein klärender Text zur Bevorzugung hybrider Verfahren
im Allgemeinfall hinzugefügt werde. Diese Darstellung widerspricht diametral
der offiziellen Zusammenfassung der Chairs, die unmissverständlich das Fehlen
von Konsens festgestellt hatten.
Dieses Vorgehen verstößt gegen ein fundamentales Prinzip des IETF-Prozesses:
Man kann keinen Konsens für Maßnahme X feststellen und diesen nachträglich in
Konsens für Maßnahme Y umdeuten, ohne eine erneute Konsultation der WG. Die
Legitimität des gesamten Verfahrens hängt davon ab, dass Entscheidungen
transparent kommuniziert und nicht im Nachhinein reinterpretiert werden."
[5] https://mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr6vgdjivHGj1mxCun3Rs/
"This would imply:
- U.S. intelligence service: 6
- UK intelligence service: 3
- Canadian intelligence service: 2"
[6] https://mailarchive.ietf.org/arch/msg/tls/vFu5iq8gPQFByj4L0hkCEAJUR9I/
[7] https://mailarchive.ietf.org/arch/msg/tls/UDvPmpd0jIpcFkLgoZZSWlcH6Ok/
"which you decided not to answer"
[8] https://mailarchive.ietf.org/arch/msg/tls/qijfEh8nZeMj0KqwRQDOBhITzfs/
> Am 14.07.2026 um 13:52 schrieb IAB Chair <[email protected]>:
>
> TLS WG,
> The IAB notes that its response to Daniel J. Bernstein’s 2026-04-24 appeal is
> being cited in ongoing working group discussion. To prevent that response
> from being read more broadly than intended, the IAB offers the clarification
> below. It takes no position on any other matter now before the WG, its
> chairs, or the IESG.
> The IAB denied the appeal. It did not find that the chairs' determination of
> rough consensus to adopt fell outside the discretion that RFC 2418 affords
> them, nor that the responsible AD and the IESG acted outside their process
> role in declining to overturn that determination.
> The relevant observation regarding the responsible AD was narrow. The IAB
> noted that the initial characterization of the adoption call by the
> responsible AD did not accurately describe the record, and that a more
> precise account followed. It was offered as encouragement to chairs and ADs
> to take care when summarizing participant responses. The observation
> concerned the accuracy of that account, not the intent behind it. It was not
> a finding that the responsible AD acted in bad faith, engaged in misconduct,
> or breached the IETF’s conduct norms.
> The IAB has also seen its response read as reaching conclusions it did not
> state. The IAB did not determine that consensus to adopt was absent, nor did
> it overturn any consensus call. Its response should not be read as reaching
> conclusions on matters beyond the appeal, including the subsequent working
> group last call or the fact that a different Area Director became responsible
> for the working group.
> Dhruv Dhody,
> (as IAB Chair, for the IAB)
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]