"For the rocky parts of the discussion: the people that give you the name they 
use in real life and tell you that they work at the NSA are not the ones to 
worry about. That's fair dealing, and we try to be open to everyone, even when 
there are pretty serious philosophical disagreements."

Our stance must remain open, within the limits of core RFCs.

RFC 8890 ("The Internet is for End Users") [1] stands in direct conflict with 
the NSA's strategic goals of weakening internet encryption and planting back 
doors through clandestine operations [2]:

    "The SIGINT Enabling Project actively engages the US and foreign IT 
industries to covertly influence and/or overtly leverage their commercial 
products' designs."
    "These design changes make the systems in question exploitable through 
SIGINT collection (e.g., Endpoint, MidPoint, etc.) with foreknowledge of the 
modification. To the consumer and other adversaries, however, the systems' 
security remains intact."
    "Insert vulnerabilities into commercial encryption systems, IT systems, 
networks, and endpoint communications devices used by targets."
    "Influence policies, standards and specification for commercial public key 
technologies."
    "civilian pay and benefits"

Please note that the phrasing "consumer and other adversaries" implies that the 
"consumer" (in RFC terminology, the "end-user") is considered an adversary by 
the NSA.

Consequently, by prioritizing end-users, the IETF would also be considered an 
adversary by the NSA.

Kind regards,

Ken Kubota

____________________________________________________

Ken Kubota
https://doi.org/10.4444/100



[1] https://www.rfc-editor.org/rfc/rfc8890.html

[2] https://www.eff.org/files/2014/04/09/20130905-guard-sigint_enabling.pdf



> Am 18.07.2026 um 19:04 schrieb Rob Sayre <[email protected]>:
> 
> On Sat, Jul 18, 2026 at 9:26 AM Jacob Appelbaum <[email protected] 
> <mailto:[email protected]>> wrote:
>> 
>> 
>> Rob's (it was Rob, right?) suggestion appears to be a viable fallback.
>> The Independent Stream does not require IETF rough consensus, although
>> it is not an automatic bypass: the authors and ISE would have to pursue
>> it, and the IESG would still conduct the RFC 5742 conflict review
>> [0][1]. I note that the authors have largely not engaged in discussion.
> 
> I think I reached for it, but it's not a novel thing. We do this all of the 
> time.
> 
> For the rocky parts of the discussion: the people that give you the name they 
> use in real life and tell you that they work at the NSA are not the ones to 
> worry about. That's fair dealing, and we try to be open to everyone, even 
> when there are pretty serious philosophical disagreements.
> 
> I prefer publishing via ISE, since people are going to use this spec. But 
> Informational through the IETF is not something I would appeal. That is 
> because I favor publishing without delay, and even wrote an RFC about it. :)
> 
> thanks,
> Rob
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to