Hi Joe,
To fully understand your criticism, please respond to the following points.
1. Please quote the exact formulations from the cited emails:
https://mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr6vgdjivHGj1mxCun3Rs/
https://mailarchive.ietf.org/arch/msg/tls/NhXrBcIlWhskI8uX0CllrTxEFuU/
that, in your opinion, "violate or are close to violating the IETF Code of
Conduct."
2. Please explain why these instances constitute "personal attacks," and in
particular, how I should be able to "intimidate other participants."
I hold no decision-making authority within the IETF (except as a member of the
working group).
Consequently, I have no power to restrict anyone, and looking at the debate,
there is no indication whatsoever that anyone has been intimidated.
What I did was cite facts and interpret them regarding a potential conflict of
interest, which I consider a legitimate debate (see point 3).
It would also be helpful in this context to provide clarification as to whether
the basis of an off-list warning shifted from "mischaracterization" to
"personal attack," as described previously on this mailing list:
"1. Joseph Salowey issued me an off-list warning on July 6. He characterized my
response to Paul Wouters as a "mischaracterization" of the IAB's findings.
2. I asked him to explain how a direct quote constitutes a mischaracterization.
He could not.
3. He then pivoted the basis to "personal attack." I asked him to retract the
warning as selectively applied and shared more clear counter examples. He did
not respond." [1]
This creates the impression that "personal attack" is a standard accusation
used to silence critics.
Making these emails public, if both parties agree, would help to mitigate
repeated claims of biased behavior and to sharpen the criteria defining exactly
what constitutes a "personal attack."
You might also take into account a participant's statement in your email to me:
"Mentioning something that can be a conflict of interest doesnt violate code of
conduct or close to. Harassment gets there but this was not it." [2]
3. In RFC 7282 (On Consensus and Humming in the IETF) Section 7 [3] titled
"Five people for and one hundred people against might still be rough consensus"
a conflict of interest is described, where one side "has a very elegant
algorithm to address the issue, one which works especially well on their
particular piece of hardware," "recruits one hundred people," "mostly people
who work at the same company [...] and who never participated before," and
engages in "vote stuffing."
The conflict of interest in this scenario is clearly of a financial nature, as
the company would gain an advantage by selling their hardware ("same company,"
"especially well on their particular piece of hardware").
The underlying logic is that a conflict of interest revealed by specific
behavior must be taken into consideration when determining whether a consensus
exists.
I can immediately recall two NSA operatives and two employees of a French
defense company who exhibited the exact same voting pattern without ever
participating in the debate. One of the NSA operatives used a private account
such that many readers do not immediately recognize him as an NSA official, and
one of the two employees of the French defense company signed up solely for the
purpose of voting.
For proper procedures at the IETF -- both regarding the question of whether a
consensus exists as determined by the working group chair, and for any
participant who wishes to challenge the decision of the working group chair
according to IETF procedures -- the question of conflict of interest must be
transparent, part of the debate, and properly documented.
Moreover, the question of whether a conflict of interest exists must remain
open to discussion for every reader to determine.
The International Committee of Medical Journal Editors states this very
clearly: "Although the presence of a relationship or activity does not always
indicate a problematic influence on a paper’s content, perceptions of conflict
may erode trust in science as much as actual conflicts of interest. Ultimately,
readers must be able to make their own judgments regarding whether an author’s
relationships and activities are pertinent to a paper’s content." [4]
Furthermore, the NSA is known for conducting clandestine operations [5]:
"The SIGINT Enabling Project actively engages the US and foreign IT
industries to covertly influence and/or overtly leverage their commercial
products' designs."
"Insert vulnerabilities into commercial encryption systems, IT systems,
networks, and endpoint communications devices used by targets."
With its multi-billion dollar budget, the NSA also generally has the means to
practice social engineering, for example, by placing operatives at strategic
positions in organizations or by funding covert actors who play their role in
advancing the NSA's interests.
To make the situation even worse, companies from the communications or
"defense" sector have a financial interest in receiving large-scale government
orders, so they naturally tend to favor the NSA's position. Thus, while the
question of conflict of interest is already, to some extent, a scientific
matter -- as seen with the International Committee of Medical Journal Editors,
where the reader (scientist) ultimately must be able to "make their own
judgments" -- this becomes even more important in the context of a military
intelligence service like the NSA, known for conducting clandestine operations
and the power to also influence companies, e.g., by obtaining their support in
standardization processes.
The question of conflict of interest must be part of the debate and discussed
openly, including observations that may indicate conflicts of interest, which
also applies to the behavior of participants, as seen in the RFC example cited
above.
In particular, I find this argument disturbing: that a question regarding a
conflict of interest "was already previously appealed and answered here by the
IESG" [6] or "This matter is resolved as far as the IESG is concerned." [7]
This eliminates any possibility for a meaningful discussion about the matter,
although this matters for both scientific conduct in the field of cryptography
-- where the NSA not only attacks cryptographic algorithms but also, as
confirmed by its own leaked documents, conducts sabotage of cryptographic
standardization processes -- as well as for the question of consensus.
The question of conflict of interest was assessed by a certain entity at a
certain point in time to reach a certain decision.
Not only "[u]ltimately, readers must be able to make their own judgments" [4]
about conflicts of interest, which requires an open debate, but also all
ongoing developments must be included in it.
Simply relegating the question of conflict of interest to a certain entity's
decision at a certain time (which in this case even only referred to an earlier
decision by some other entity) is inconsistent with scientific practice (and
also not with the example set out in the RFC).
I note that I require additional time to study IETF procedures and formulate my
response.
Kind regards,
Ken Kubota
____________________________________________________
Ken Kubota
https://doi.org/10.4444/100
[1] https://mailarchive.ietf.org/arch/msg/tls/LvUiinuyMPCXTFMrbeYB0aa1Iw4/
[2] https://mailarchive.ietf.org/arch/msg/tls/P57ytYmUA6jxh_ehxR9_lMcQXQc/
[3] https://www.rfc-editor.org/rfc/rfc7282.html#section-7
[4]
https://www.icmje.org/recommendations/browse/roles-and-responsibilities/author-responsibilities--conflicts-of-interest.html
"Individuals may disagree on whether an author’s relationships or activities
represent conflicts. Although the presence of a relationship or activity does
not always indicate a problematic influence on a paper’s content, perceptions
of conflict may erode trust in science as much as actual conflicts of interest.
Ultimately, readers must be able to make their own judgments regarding whether
an author’s relationships and activities are pertinent to a paper’s content.
These judgments require transparent disclosures. An author’s complete
disclosure demonstrates a commitment to transparency and helps to maintain
trust in the scientific process."
[5] https://www.eff.org/files/2014/04/09/20130905-guard-sigint_enabling.pdf
[6] https://mailarchive.ietf.org/arch/msg/tls/wahhT6eE39viKcIusKK4dTKzcIE/
[7] https://mailarchive.ietf.org/arch/msg/tls/GQ2cEosoHH9UyKp_9tIW15BW0Cw/
> Anfang der weitergeleiteten Nachricht:
>
> Von: Ken Kubota <[email protected]>
> Betreff: [TLS] Fwd: Warning about TLS mailing list behavior
> Datum: 16. Juli 2026 um 01:20:24 MESZ
> An: [email protected]
> Kopie: [email protected], IAB Chair <[email protected]>, TLS Chairs
> <[email protected]>
>
> For your information.
>
> ____________________________________________________
>
> Ken Kubota
> https://doi.org/10.4444/100
>
>
>
>> Anfang der weitergeleiteten Nachricht:
>>
>> Von: Joseph Salowey <[email protected]>
>> Betreff: Warning about TLS mailing list behavior
>> Datum: 15. Juli 2026 um 22:02:45 MESZ
>> An: [email protected]
>>
>> HI Ken,
>>
>> You have recently sent messages to the list that violate or are close to
>> violating the IETF Code of Conduct in BCP 54 / RFC 7151. In particular we
>> have identified the following issues:
>>
>> You sent messages to the list that are personal attacks by accusing
>> individuals of conflict of interest. Examples include [1] and [2] and
>> additional messages on the list
>>
>> This can be interpreted as an attempt to intimidate other participants.
>>
>> Please keep communication on the mailing list professional and civil.
>> Consider this a private warning for inappropriate mailing list behavior;
>> required by BCP 94 / RFC 3934.
>>
>> Joe
>> TLS Working Group Co-Chair
>>
>> [1] https://mailarchive.ietf.org/arch/msg/tls/lnSPh3Wr6vgdjivHGj1mxCun3Rs/
>> [2] https://mailarchive.ietf.org/arch/msg/tls/NhXrBcIlWhskI8uX0CllrTxEFuU/
>>
>
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]