"For the rocky parts of the discussion: the people that give you the name they
use in real life and tell you that they work at the NSA are not the ones to
worry about. That's fair dealing, and we try to be open to everyone, even when
there are pretty serious philosophical disagreements."
Our stance must remain open, within the limits of core RFCs.
RFC 8890 ("The Internet is for End Users") [1] stands in direct conflict with
the NSA's strategic goals of weakening internet encryption and planting back
doors through clandestine operations [2]:
"The SIGINT Enabling Project actively engages the US and foreign IT
industries to covertly influence and/or overtly leverage their commercial
products' designs."
"These design changes make the systems in question exploitable through
SIGINT collection (e.g., Endpoint, MidPoint, etc.) with foreknowledge of the
modification. To the consumer and other adversaries, however, the systems'
security remains intact."
"Insert vulnerabilities into commercial encryption systems, IT systems,
networks, and endpoint communications devices used by targets."
"Influence policies, standards and specification for commercial public key
technologies."
"civilian pay and benefits"
Please note that the phrasing "consumer and other adversaries" implies that the
"consumer" (in RFC terminology, the "end-user") is considered an adversary by
the NSA.
Consequently, by prioritizing end-users, the IETF would also be considered an
adversary by the NSA.
Kind regards,
Ken Kubota
____________________________________________________
Ken Kubota
https://doi.org/10.4444/100
[1] https://www.rfc-editor.org/rfc/rfc8890.html
[2] https://www.eff.org/files/2014/04/09/20130905-guard-sigint_enabling.pdf
> Am 18.07.2026 um 19:04 schrieb Rob Sayre <[email protected]>:
>
> On Sat, Jul 18, 2026 at 9:26 AM Jacob Appelbaum <[email protected]
> <mailto:[email protected]>> wrote:
>>
>>
>> Rob's (it was Rob, right?) suggestion appears to be a viable fallback.
>> The Independent Stream does not require IETF rough consensus, although
>> it is not an automatic bypass: the authors and ISE would have to pursue
>> it, and the IESG would still conduct the RFC 5742 conflict review
>> [0][1]. I note that the authors have largely not engaged in discussion.
>
> I think I reached for it, but it's not a novel thing. We do this all of the
> time.
>
> For the rocky parts of the discussion: the people that give you the name they
> use in real life and tell you that they work at the NSA are not the ones to
> worry about. That's fair dealing, and we try to be open to everyone, even
> when there are pretty serious philosophical disagreements.
>
> I prefer publishing via ISE, since people are going to use this spec. But
> Informational through the IETF is not something I would appeal. That is
> because I favor publishing without delay, and even wrote an RFC about it. :)
>
> thanks,
> Rob
> _______________________________________________
> TLS mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]