[Ssh] Re: Moderation pitfalls in practice ( was Re: Re: WG Review: Secure Shell Maintenance (sshm))

Jan Schermer <jan@schermer.cz> Sat, 07 September 2024 21:11 UTC

Return-Path: <zviratko@zviratko.net>
X-Original-To: ssh@ietfa.amsl.com
Delivered-To: ssh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 607D5C14F68C for <ssh@ietfa.amsl.com>; Sat, 7 Sep 2024 14:11:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.656
X-Spam-Level:
X-Spam-Status: No, score=-1.656 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=zviratko-net.20230601.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GGLoANndyPNz for <ssh@ietfa.amsl.com>; Sat, 7 Sep 2024 14:11:03 -0700 (PDT)
Received: from mail-wr1-x429.google.com (mail-wr1-x429.google.com [IPv6:2a00:1450:4864:20::429]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AC6A1C14F5F6 for <SSH@ietf.org>; Sat, 7 Sep 2024 14:11:02 -0700 (PDT)
Received: by mail-wr1-x429.google.com with SMTP id ffacd0b85a97d-3780c8d689aso1880158f8f.0 for <SSH@ietf.org>; Sat, 07 Sep 2024 14:11:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zviratko-net.20230601.gappssmtp.com; s=20230601; t=1725743460; x=1726348260; darn=ietf.org; h=message-id:in-reply-to:to:references:date:subject:mime-version:from :from:to:cc:subject:date:message-id:reply-to; bh=V/NqXcrkvqMuXSolDHSSUMS9A7MaNQz+yTBuZgRU+t0=; b=r46eTY1/H3emVNJpnN8uu3WkKl2U/6+dHfMRqPTbUxpiq5Kd1ZtQPaPviS8MZsd2Fq VrDqhHogUg7Qk34o7hLammgkU5QzoMzRY59aD0Bi8oeGJdOvrA5FVpwpYmwBlFEx/BJT iM8L1ggyDqqScOiRE7/q+9eekhQDvDEqfAm9J9mcgbbSxbamkj5gnC2FYXC5+LkLMvjU MrIIEm9XQD8e84Z++xIJkUsRIIDALOkXkwC+m8othIeye5wbNDr0FojTWNcKrKuDH7h0 WGMm1iLupRXge9x83/Yrb5Mwj3x/gbeMXMb+rZ8pUUml3HmY1+C0dorNun+8KD68oJLg O06A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1725743460; x=1726348260; h=message-id:in-reply-to:to:references:date:subject:mime-version:from :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=V/NqXcrkvqMuXSolDHSSUMS9A7MaNQz+yTBuZgRU+t0=; b=xSsvNeN8yE64Hakv4ZMYml4rXq8iTQ9Bs9B8esXDlAdux2HgyT0fbeqCpiZAEHTQ8y PA1CsR8YjpdCR6sp5tVw9LRvQhG2fwX9W+BFAH4AG3XTAaUG9lg8Co2r3Tz/XkyCuLhy Y7H8dZwCTSnKjEDmEwyCJP/FykgjekBnUUv7R4ulCuX3/b/gW7VKpxcHmEJpv7yuvmVR PfpDdtiM5wzzLpvO9V/UicRDdiLSPsBuzCrjcOHF4IH8xs3oKDZpCq9x7LtI6MdbkV9x BI5FtYcOMGvUKCzhEt+LCATSrGV3axxlTkUvMLXv/+Hy85ETTnlaFXJYu2F5h2RgnG5r 4s1Q==
X-Gm-Message-State: AOJu0Yw+rPYe1pzKY/XNGKDoflIggbHOZzmdBW8zQrJsDt11RfhA2SFP zEIDF4LwNZiqX+YybEYX172COYsGbIRww8wPNy6GnOFRVq1YLVvh4Bl7fBkn8xry7SoSUuBXezP 8bpI=
X-Google-Smtp-Source: AGHT+IERoBCl2/eMmaxyVShIiTZj7uG0mriwTPTT8Ig6n+TbWgEmQSbvXC5cK4dBtHkIGO8ygxEnbQ==
X-Received: by 2002:a5d:558d:0:b0:374:c671:2324 with SMTP id ffacd0b85a97d-378896591d5mr3662989f8f.44.1725743459349; Sat, 07 Sep 2024 14:10:59 -0700 (PDT)
Received: from smtpclient.apple ([188.75.128.215]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-42caeb8120asm25929215e9.37.2024.09.07.14.10.58 for <SSH@ietf.org> (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 07 Sep 2024 14:10:58 -0700 (PDT)
From: Jan Schermer <jan@schermer.cz>
Content-Type: multipart/alternative; boundary="Apple-Mail=_FC5524D7-C79E-4484-8B82-4352FC365CA6"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.200.46\))
Date: Sat, 07 Sep 2024 23:10:48 +0200
References: <20240907053247.216374.qmail@cr.yp.to> <0f5f36bd-b2a8-c57b-e0f8-ab98c42808e0@nohats.ca> <CACsn0cmq4ab-7_GDPhc6UzNtx51OVPKQYo7dGcPUaQpE2qe6Nw@mail.gmail.com>
To: SSH@ietf.org
In-Reply-To: <CACsn0cmq4ab-7_GDPhc6UzNtx51OVPKQYo7dGcPUaQpE2qe6Nw@mail.gmail.com>
Message-Id: <3177E31F-17BA-462C-ACF2-FAD3DA0E294D@schermer.cz>
X-Mailer: Apple Mail (2.3826.200.46)
Message-ID-Hash: QP7AJXW2GTDQDHVMDFDZOUENK2K3ZPIY
X-Message-ID-Hash: QP7AJXW2GTDQDHVMDFDZOUENK2K3ZPIY
X-MailFrom: zviratko@zviratko.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Ssh] Re: Moderation pitfalls in practice ( was Re: Re: WG Review: Secure Shell Maintenance (sshm))
List-Id: "The SSH mail list will allow discussions on improving aspects of the Secure Shell (SSH) protocol." <ssh.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ssh/HPZ1H0H_wi25dlCykGOdCRvWno4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ssh>
List-Help: <mailto:ssh-request@ietf.org?subject=help>
List-Owner: <mailto:ssh-owner@ietf.org>
List-Post: <mailto:ssh@ietf.org>
List-Subscribe: <mailto:ssh-join@ietf.org>
List-Unsubscribe: <mailto:ssh-leave@ietf.org>

Well said.
Fortunately, such institutional behaviour doesn’t discourage nor prevent all expression, like mine:

While DJB’s statements might well be viewed as abrasive, I believe he has proven to try to act in the best interest of the internet society (so… in fact everyone) and has a track record of actually working towards that goal (and also of being subverted and ignored by various organizations).

SSH is absolutely critical to day-to-day operations and security of everything and everyone operating anything connected to the internet. It should be able to be subjected to the utmost scrutiny, warranted or not. All questions should be answered factually, all decisions should be based in fact. I feel this effort is a bit one-sided here.
Also, while I have not taken interest in the inner workings of IETF before this (I only joined this ML because I was one the SSH mailing list and curious), what I’m seeing here is tragic. Unless I’m missing the forest for the trees (like that IETF actually is trying to work more like NASA than NASA, all the SSH developers _are_ actually looking forward to working in a glorious WG and its output is going to be wondrous), then this all looks like bureaucratic exercise of politicians and a push for some sort of control, not at all like what real OSS development discourse looks like. (Sorry in advance to those feeling personally hit by the realization they have become a slowly boiled frog)
I am not going to comment on the facts themselves, as I wasn’t able to follow all the discussions, but those few I have (because the post was by someone I actually know is respectable) raise good questions with no good answers, like the correlation with the NIST PQC debacle.

I might be factually, actually and completely in error, as I am not a SSH dev, not really a participant (current or past) of the process, nor do I know the history behind SSH+IETF(+DJB+NSA+OpenBSD foundation+whateverElse).
I am, however, a concerned and frankly alarmed member of the public, and this is what this looks like from outside.

In the light of exposed malpractice by similar historically engineering-first organisations, I think it’s not unreasonable to prefer leaving SSH development and governance to the engineers instead of … whatever this is, and to heavily question every decision and intent or conflict of interest. 

In the end, I would advocate for the analogue of “vote with your wallet” by “voting with code” - I know I’m going to trust OpenBSD/OpenSSH devs (et al.) when they introduce a “new” unsanctioned cipher by DJB, and I won’t question them for not including KyberGarbage, no matter what IETF RFC says.

Do with this input as you will.

Jan


> On 7. 9. 2024, at 21:02, Watson Ladd <watsonbladd@gmail.com> wrote:
> 
> That's even more true when the person who is among the subjects of the
> complaint is making the action. i don't think its impossible to
> navigate through them, but it requires care, and a blanket statement
> of the nature that "speculation of IESG malevolence has no place in
> IETF discourse" is the sort of overbroad, impulsive statement that
> doesn't need to be made in the form it is here, reads very differently
> in a moderation action than elsewhere, and probably makes people less
> willing to express their views on important matters related to what
> SSH WG would look like.