>It doesn't matter if Deb is a great neighbor, or how many colleagues send 
>spooky and supportive e-mails.

I think many people are concerned that Deb might simply decide to step away 
from the IETF and, rather than continue devoting so much unpaid time and effort 
to IETF work, choose to enjoy her retirement instead.

The appropriate time to discuss whether Deb was suitable to become an AD was 
during the election process.

>There is a reason that judges, regulators, and board members recuse themselves 
>when a structural bias exists. Yet, this did not happen here.

As the chair of a board, I often have to consider these kinds of issues. I do 
not think that having previously worked for the NSA, by itself, constitutes a 
conflict of interest. By contrast, participating in discussions about whether 
one's own research should be standardized seems like a much clearer potential 
conflict of interest. Do you think Bernstein should recuse himself or declare a 
conflict of interest every time X25519, ChaCha20, Poly1305, Classic McEliece, 
SLH-DSA, or NTRU Prime is discussed?

Cheers,
John Preuß Matttsson

From: Andrew Lee <[email protected]>
Date: Thursday, 16 July 2026 at 18:23
To: Scott Fluhrer (sfluhrer) <[email protected]>
Cc: Tim Hollebeek <[email protected]>; Ryan Hurst 
<[email protected]>; TLS List <[email protected]>
Subject: [TLS] Re: Response to CoI Complaints

It's clear that Deb is a professional based on the countless responses in this 
thread!!

Now that we have established this, I'd also like to point out that nobody 
asked, and further, this is quite off topic [1].

Furthermore, the issue isn't whether or not Deb Cooley is a person of proper 
moral turpitude. Instead, it's whether a 37-year NSA veteran can serve as a 
neutral arbiter in a process where NSA employees are flooding the list in 
support, most of whom are participating for their first time, where NSA's CNSA 
2.0 framework requires the exact outcome the NSA desires from this process, and 
where NSA's Canadian partner stated on-list [2] that they are waiting for this 
RFC so they can recommend solo ML-KEM nationally.


"This is not a conflict of interest," said nobody, ever.


It doesn't matter if Deb is a great neighbor, or how many colleagues send 
spooky and supportive e-mails. There is a reason that judges, regulators, and 
board members recuse themselves when a structural bias exists. Yet, this did 
not happen here.

Deb writes that "retired does not mean ... 'defected'." I agree. It also 
doesn't mean independent.

Also, I want to reiterate something I mentioned to the Cypherpunks: The NSA 
recruits some of the best and brightest people. The kind of people you really 
want to have as a good ol' neighbor. These are the most principled, most 
talented people who are genuinely dedicated to public service.

This is precisely why the NSA is so effective.

The NSA is not an institution of villainry. It is a team of really good people, 
who are convinced by an institution they trust, to spy on their neighbors.

DES, Dual EC, the SIGINT Enabling Project and its quarter-billion-dollar annual 
budget to "covertly influence" standards [3] was carried out by professionals 
with the utmost belief they were protecting their country. In other words, it 
is not Deb Cooley, the person, that concerns me.

The issue is that a lifelong member of the NSA has utmost control over the 
consensus process of security decisions that affect billions of people. If we 
are to accept that 37 years at NSA creates no institutional bias on a question 
that directly serves NSA's stated mission, then the concept of conflict of 
interest has no meaning.

Finally, Tim noted that it will be "impossible to find Area Directors" if 
structural concerns are raised. Please, allow me to fix this for you: it will 
be impossible to trust Area Directors if structural concerns cannot be raised.

Another participant, Thomas, even went so far as to say that we may be 
"reaching the limits of the open society model."

Yet, there was not a single response to the following:
- Uri, an MS holder, called PhD holders and full professors "crypto-wannabes 
who are now flooding this list"
- Paul accused participants of "consensus manipulation" while said subject was 
under moderation and unable to respond
- etc.

Meanwhile, Dr. Bernstein is still moderated for a footnote as Ted pointed out.

If we are currently living in an Isekai where the heroes are, unpredictably, 
the most hated in society, then everything here makes sense.

Sincerely,
Andrew

[1] https://mailarchive.ietf.org/arch/msg/tls/VowJMoJE2nfD83sY6KEoqKIIBgA/
[2] https://mailarchive.ietf.org/arch/msg/tls/uOeM5IRcYYjpNFlRyxEfo91q29c/
[3] https://www.eff.org/files/2014/04/09/20130905-guard-sigint_enabling.pdf

On Jul 16, 2026, at 8:38 AM, Scott Fluhrer (sfluhrer) 
<[email protected]> wrote:

I agree; in my experience, Deb has always acted honorably and professionally.

Remember what it says in the Note Well: "Attack the idea.  Don't attack the 
person"

________________________________
From: Tim Hollebeek <[email protected]>
Sent: Thursday, July 16, 2026 10:49 AM
To: Ryan Hurst <[email protected]>; Deb Cooley <[email protected]>
Cc: TLS List <[email protected]>
Subject: [TLS] Re: Response to CoI Complaints

I completely agree with Ryan. These baseless accusations have no place at IETF. 
It's going to be impossible to find Area Directors in the future if this sort 
of behavior is deemed acceptable. Nobody should have to put up with these sorts 
of attacks.

-Tim
________________________________
From: Ryan Hurst <[email protected]>
Sent: Wednesday, July 15, 2026 6:38 PM
To: Deb Cooley <[email protected]>
Cc: TLS List <[email protected]>
Subject: [TLS] Re: Response to CoI Complaints

I have known Deb professionally and through the standards community for more 
than a decade. She is one of the most hardworking, principled, and 
public-service-minded people I have encountered in this field.
You may disagree with Deb’s technical conclusions. You may disagree with how 
she has handled a particular matter as Security Area Director. Those 
disagreements are legitimate, and the IETF has well-established processes for 
raising them.
What is not legitimate is turning those disagreements into insinuations about 
her integrity, loyalty, or professional history. Referring to someone who 
completed more than 37 years of public service and then retired as having 
“defected” is not criticism. It is a personal smear, and an especially ugly one.
Deb has spent decades doing difficult, consequential, and often thankless work. 
In every interaction I have had with her, she has shown up prepared, engaged 
seriously with the substance, and acted according to her principles even when 
doing so was difficult or unpopular.
Deb has earned better than this from the community she has served.
Ryan Hurst

On Wed, Jul 15, 2026 at 11:51 AM Deb Cooley 
<[email protected]<mailto:[email protected]>> wrote:

For the record:  I have been a Security Area Director since March 2024, that is 
2 years and a couple of months.

There have been previous inquiries into my ability to perform the duties of 
Security Area Director  via the SSHM working group, and as part of complaints 
against the TLS chairs/AD.  Those have been responded to by the IESG, the 
artifacts are below:

https://mailarchive.ietf.org/arch/msg/ssh/7KRZCX_bvZWUOG50HqDg_KVT77c/<https://url.avanan.click/v2/r01/___https://mailarchive.ietf.org/arch/msg/ssh/7KRZCX_bvZWUOG50HqDg_KVT77c/___.YXAzOmRpZ2ljZXJ0OmE6bzpiYmE3MTIwOTRkMDZlNTEzNGFmM2IxMjVlY2U5ZTJiODo3OmVlNTY6YjJmM2YyM2U2MGMwOWRkMTYzY2Y1NDMwZDNmOGM4Yjg4ZjdjNThiYTZiMDQyMzg3NzM0MmEwMjFhMmFmOTUwNTpoOlQ6Rg>
https://datatracker.ietf.org/group/iesg/appeals/<https://url.avanan.click/v2/r01/___https://datatracker.ietf.org/group/iesg/appeals/___.YXAzOmRpZ2ljZXJ0OmE6bzpiYmE3MTIwOTRkMDZlNTEzNGFmM2IxMjVlY2U5ZTJiODo3OmVmYTA6MWYwMTkwMTc2MmM5ZTAxZmU2YWE2OTE1ODFiMTRlZjA3ZWY0YTk4NjY3MjRjZjhlYjQxM2E1NGQwNmExODI5YzpoOlQ6Rg>
 (see artifacts 125/126, as well as 128/129)

In addition to the artifacts above, I suggest that there might be people for 
whom I have worked with that could give an opinion on my work ethic and conduct 
for the last 2 plus years.

The recourse for anyone who doesn’t believe this is a sufficient response is 
free to take a look at [RFC 8713, Section 
7](https://www.rfc-editor.org/info/rfc8713/#section-7<https://url.avanan.click/v2/r01/___https://www.rfc-editor.org/info/rfc8713/%23section-7___.YXAzOmRpZ2ljZXJ0OmE6bzpiYmE3MTIwOTRkMDZlNTEzNGFmM2IxMjVlY2U5ZTJiODo3OmNiZGM6ZTg4ZTM3Mzk2MjAzZDJiMzU1OTJmZWIzNDg3MGNkN2E1ZTBiMTQ3YWJkZDQ0YTUwOWQ1NjE2MTJmMjQ0ZjljYzpoOlQ6Rg>).

Just a couple of minor points:
1.  Retirement means that I don't work for NSA anymore.  I earn no salary.
2.  Retired does not mean the same as 'defected'.
3.  My bio is accurate see here:  
https://datatracker.ietf.org/person/Deb%20Cooley<https://url.avanan.click/v2/r01/___https://datatracker.ietf.org/person/Deb%20Cooley___.YXAzOmRpZ2ljZXJ0OmE6bzpiYmE3MTIwOTRkMDZlNTEzNGFmM2IxMjVlY2U5ZTJiODo3OjQ4Yjg6NDc4NTIzN2VjMTU4NGI5OGQxOGRjY2Y3ODBjMWY3Zjc1NGE4ODM2MTBmMWE5NzYyYTc1NTUzY2RjYWIxZjlmZDpoOlQ6Rg>.
 37+ years of service in Cybersecurity which used to be Information Assurance, 
which used to be Information Security, which used to be COMSEC.
4.  If you read RFC 9151, read all of it.  Section 6 and 7 have MAY 
requirements which improve interoperability.  Note that the draft was published 
in February 2021 when Adrian Farrel was the ISE.  It was reviewed by a 
noteworthy set of reviewers including the late Jim Schaad.


Deb Cooley
Sec AD
_______________________________________________
TLS mailing list -- [email protected]<mailto:[email protected]>
To unsubscribe send an email to [email protected]<mailto:[email protected]>
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to