[TLS] Re: Improving the quality of the discussion on the TLS email list

Joseph Salowey <joe@salowey.net> Mon, 03 August 2026 18:21 UTC

Return-Path: <joe@salowey.net>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 7577E122E149C for <tls@mail2.ietf.org>; Mon, 3 Aug 2026 11:21:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785781319; bh=R3u0yEBAG+91hl39EZMS11rnzrNw4QTwIu2swOsJCeo=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=VZywFFuuldZg+7K3YKFWYi7IULB0L/wImhtRsCo760tdoxiX2YtquJ53slZW907hk /cx0Z7Tj7xEgh5u91gWpXSBrvP+TLxbaLsviCbQJmzms6mRTpyjYNyBeSaMtvkEuJx fsiWB1cK7P6FIm4Cvag1aGfopupTAdQQNCPcQj0E=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=salowey-net.20251104.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2FSIBl8_cK5c for <tls@mail2.ietf.org>; Mon, 3 Aug 2026 11:21:58 -0700 (PDT)
Received: from mail-pl1-x635.google.com (mail-pl1-x635.google.com [IPv6:2607:f8b0:4864:20::635]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5F08E122E1478 for <tls@ietf.org>; Mon, 3 Aug 2026 11:21:58 -0700 (PDT)
Received: by mail-pl1-x635.google.com with SMTP id d9443c01a7336-2cab973140bso46372525ad.3 for <tls@ietf.org>; Mon, 03 Aug 2026 11:21:58 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785781317; cv=none; d=google.com; s=arc-20260327; b=MqRR+dRoV/tKLFb4NwTX3DIVL1yypINEmnIp+cWBx6gcPwRMYXXmcXIGnFwMbbJiAD xB30obzFF8xhs6ZVKzQU3zrBb45Ak1S1xxINRpud+U+QvJqmK22VWpywbzZFBCX8joqP y0fd9DL+vTpd728AlpDOShK4QWrPYk1O0z1gzpX21L9isMpFFYuX/fqIHystXCfLrlrT 9vEplERKaqSt5FziXkawm62YOrYaWlknO+VQGXMQU/iTdq8rVdfXbl+HQDtiSkb01Heo XKvpxynIl5Wz5XkI3lVAmv5urqHhmFIvZNfuUfoFo9ySi2skCyBXcpH1HPKRRHrXcjgl ReRA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=9bTOxi3/bLq6kXxIYgrdA18QbR3wcbjqrfvmtopfcVc=; fh=EXNpBMDH5VlQXu414NtBrMbknfHKzD0d9I0Qp3r0ctY=; b=Oc9MzJIrTDOTUfSeBP5jGtHalF33poww7+grBM8Mjx6RccSLtSrFeC4tO2/75SZHwJ nzG9wJDVGSAU+G6vtL06Mc7WfEt/2tpBhNSeHTMOAkyxMedCI906eGKwY9B+HAgTmcnv 4MeS9VJ2exwwhW+IlFKAPfPqGsAYsj5KSEpzWiNbXQCnKFqHwoT0I44F+dd3qyyP6VQS VbMTmxF0O5ejN/HIvv2qdhRb3bRCBmYjyZv8tyVbcKxl3HixuwnXONJ9eZ28fiKsXJas 5zilaw24ZhH8txjwGIihRMss+rkvf1vybwB/+/A43aJ9oFiG623E4tUn2B8n70cXTFk6 8qjA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=salowey-net.20251104.gappssmtp.com; s=20251104; t=1785781317; x=1786386117; darn=ietf.org; h=content-transfer-encoding:content-type:cc:to:subject:message-id :date:from:in-reply-to:references:mime-version:from:to:cc:subject :date:message-id:reply-to:content-type; bh=9bTOxi3/bLq6kXxIYgrdA18QbR3wcbjqrfvmtopfcVc=; b=uB4hbh8GoLMTKcdzKXEZZInSR3o7Z3A5ZK8zNxhYQ9OxSI84aZYHanr2aRHIVX3VwB /ETSnpDqHNg8Y5WODAms7/4SaXDrvrM8yF97FWh8WmYDyx01xKHZ/IykrSdjCLoC3Hhe DvE8YG8iC+VWRavXgQrXcI7D+gyrtl4WteUTlNqIxl07nNKOlZQ1UEiYb/Guf/tetr01 x+95Y5HCZ3dlKYMTcM+2+xBK+Hpz0P6HL4r8/q9BJUrngxrBrrU46HDC9U1wNNg9Koc4 TNfn+1IkHiAsHhRbip1JhpvIK+Qpnl4pBG8lQZ2sftc8wrz97rf81QxInt4L3VDTneIn jnbg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785781317; x=1786386117; h=content-transfer-encoding:content-type:cc:to:subject:message-id :date:from:in-reply-to:references:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=9bTOxi3/bLq6kXxIYgrdA18QbR3wcbjqrfvmtopfcVc=; b=Y4Ysts2xCs7bqR6J4Mp2YIbHxLwVpdRBVG02mRg6aN/GKqRPgbsv4HpCpNbSmaiZQU RZH44hGVa8BZx/9r6zGFNAqyVsTDqBCWHdsWibOT7a0Ho82YI4v4MVAFiRcFm3tHgnnF 2NyBIJQAjPAnGfVLBBC1/DS1OsNMiyJCBtlhmh6fjfLN6NRONZfQqlS342kKZLt2jzMm +gWgvI6R0DRCrEkAt8YtnuzI5AaujnTfsVJx0glxsQ2Zj6TNwCmgX0kqy7+b8unIzTlx p59Rzqf/37qtTdwgx7pbsbiOeTdRpH5LpuinCk6QusGzhkL7p06bZ2k0TSkBf/RmTo/e soHA==
X-Gm-Message-State: AOJu0Yxmlj2BjD7ZQWKdRuZp6rkm7igldSZC4m89g5swKP8e4LRJfeee upDcMT+cPmKtyxYBo6gXLJUsk9cM3K3yPWFqoBhD4alVZsOODdnLWywLAjoESaRA5I+OK4E4yqQ jV+SpHFaSRUGfvCV6SfQhsZbgbOnUZ8EOQA8kTxrvMkh27LhCZU5UfASDVg==
X-Gm-Gg: AR+sD11lw+wmYllifY2h/aLMjJE2mbqxu/C7OGHJar7Bs5Ow+oWL0QK+nRpr26uJTq/ JWzvFqkn783YJt8JCRktwdHA5IJM9aOFiO2ewugoJcZawx8a0WDW2Ny+ucvqWcDn6Fn48GSXJov VAD6itSrJ8rqLto9V4Ge/XlrrXJg9p1dEdR0qAfl5ob0CSBs+U98DMi5BSb63PvWu2i8KUdDiKw cI+vzfZblGPxn6GmOnrp4I1lhA+130M2Jz9hFe7dn2sVpHtPUolvlpzr6gcKdcB8wR/82qnuRJr q26NQQFtdPBEY8rZkziua70sTk43QkmYpgnijHeu5CI=
X-Received: by 2002:a17:902:e54f:b0:2cc:c9cb:371c with SMTP id d9443c01a7336-2d0523f2175mr117406095ad.40.1785781317410; Mon, 03 Aug 2026 11:21:57 -0700 (PDT)
MIME-Version: 1.0
References: <CAEzBKQ4fymnSeo8tgqMLOfKopvMGk4xnDq=SQJKf-RBL4-uh6g@mail.gmail.com> <CAEEbLAbhZUpempA9Rvjhm1qrLfBWXa_2ntdfpO20cqDu0h5fbQ@mail.gmail.com> <CAEzBKQ6NOzQc66T+SEdSvLa2gxjtO77DYUUWuTfr99zV_a-Ofg@mail.gmail.com> <c8a74833-35cd-44a0-8992-e5463a82aa8f@dennis-jackson.uk> <F95592F7-6E60-4835-B21C-B5B1954084F7@kenkubota.de> <b3321e23-5f9b-4f8a-8bd9-d2cca2800d67@lear.ch> <amypaHNTh0Ya7XF+@ein.win.tue.nl> <538b6162-6cbb-4051-9810-601b29f880fe@app.fastmail.com> <CAA+_yBYWP_3MOcTM8FH8wjiif_L_WLOPVHKnp8nVmGJzFiCCpQ@mail.gmail.com> <f5cb425b-6fd4-48f2-aec0-5272e9ff30fe@app.fastmail.com> <0F869FB6-FAF9-4DBB-A046-3ABEA0A14C44@joseon.com>
In-Reply-To: <0F869FB6-FAF9-4DBB-A046-3ABEA0A14C44@joseon.com>
From: Joseph Salowey <joe@salowey.net>
Date: Mon, 03 Aug 2026 11:21:45 -0700
X-Gm-Features: AUfX_mwsAEj46rDjWPl0_NOX6UTNPBeLgZpJkA0UHqgOZX83QUdUwd6isyKSIzU
Message-ID: <CAOgPGoBnKOxdaWCBQfyG0NTuC1q09MyuqynVD7JCrsXOApgQaQ@mail.gmail.com>
To: tls@ietf.org
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: 7IGZ2O563UWGIDOHN6XYP65BQNFD4L3F
X-Message-ID-Hash: 7IGZ2O563UWGIDOHN6XYP65BQNFD4L3F
X-MailFrom: joe@salowey.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Andrew Lee <andrew@joseon.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Improving the quality of the discussion on the TLS email list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/ckh4S8usKpKrp_Ai12xAAJzdHQs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

The primary task of the chairs during a consensus call is to review
all feedback for substantive, unaddressed technical information and to
identify underlying consensus patterns. Consensus is determined by
assessing the quality and resolution of technical arguments rather
than by simple counts. No message or opinion was discarded based on
counts or metrics.

To address a specific query directly:

Off-list messages were not factored into any "count". No participants
were moderated at the start of this WGLC. In the case of DJB, his "No"
consensus position was already fully registered and factored into the
evaluation prior to his moderation.

Based on this technical evaluation, the chairs determine document
updates and judge the rough consensus of the working group. The issues
we covered in the last call resolution were:

- More emphasis on the document's recommended status
- Randomness requirements discussion
- Document track and stream discussion

We are now locking this thread subject, which means people can start
new threads, but their messages will be held if they reply to this
one.

On Fri, Jul 31, 2026 at 11:51 AM Andrew Lee <andrew@joseon.com> wrote:
>
> Dearest Filippo,
>
> Suggesting that Dr. Lange and Dr. Dunkelman somehow reverse engineer the chairs' methodology is far from a serious response.
>
> Nobody should have to guess at blackbox processes when it comes to the security of the billions of people on the internet. Further, an appeal cannot be conducted when the process which produced the outcome is unclear.
>
> I'd like to remind everyone what happened during this Solo ML-KEM rough consensus determination exercise:
>
> 1. Not 1, not 2 but 3 WGLCs were conducted.
> 2. The AD issued statements about misrepresentation that occurred during one of the WGLCs.
> 3. Cleary, messages were both filtered and moderated.
> 4. The hero who won the people of the world the right to write, research and distribute cryptography was moderated from participating on the list during the process due to a common footnote that was, simultaneously, found and ignored from other participants.
> 5. This is already enough without having to mention the peculiarities relating to the sudden involvement from intelligence agencies.
>
> Nobody is asking for an itemized vote list, Mr. Valsorda. However, I can understand why the distinguished PhD cryptographers on this list are concerned with the alarming conclusion to the rough consensus process... since we didn't hum [1], nor did we use a formal count to arrive at an outcome that contradicts what was suggested by nearly every discerning PhD and professor on the list.
>
> So it's a pretty simple ask:
>
> 1. What counted as prior participation,
> 2. What counted as demonstrated domain expertise, AND
> 3. Were off list and moderated messages taken into consideration?
>
> If the process was legit, it should cost nothing to be transparent.  That said, the continued refusal to provide these details is actively being written into history.
>
> At best, this process looks Mickey Mouse... at worst, infiltrated.
>
> Sincerely,
> Andrew
>
> [1] https://datatracker.ietf.org/doc/html/rfc7282
>
> On Jul 31, 2026, at 10:53 AM, Filippo Valsorda <filippo@ml.filippo.io> wrote:
>
> Hi Orr,
>
> Emphasis added:
>
> Then, have you tried tallying support by “pre-existing WG participants or people with demonstrated expertise” using your own methodology? Did you land at a result significantly different from “roughly 7/10”?
>
>
> I have high confidence that Tanja, or you if you want to help, can give it a useful try.
>
> 2026-07-31 19:10 GMT+02:00 Orr Dunkelman <orrd@cs.haifa.ac.il>:
>
> As the ADs did not publicly release the criteria relevant to what is considered "prior involvement" (would participation in one discussion before the ML-KEM sufficient to be considered in this set of voices?) nor what are the "experienced people" they deemed to be worthy of being heard (i.e., newcomers who are experienced), it is a bit impossible to make the statistics you have asked Tanja to make. Actually, even putting aside mailing issues, moderation problems, and assuming that indeed all the votes were indeed public, no one but the ADs can make these statistics. This is exactly what reasonable people asked for in this mailing list (including people from academia, industry and government) - to get these criteria publicly available. Hence, contacting IESG, IAB, the UN, or even the local fire brigade, is useless until the ADs supply this information.
>
> Furthermore, during the discussion I've pointed out that one of the co-designers of MLKEM found the idea of standardizing only MLKEM to be premature. I am sure that when assigning weights to participants, one of the guys inventing the thing (and especially as this particular individual has years of experience in industry, so this is not just a theoretical computer scientist with no understanding of the real world), should probably get a somewhat higher weight than even people who participated in past TLS discussions. As the ADs did not report counting this specific individual's "vote" (that says that the entire idea is bad) it is unclear whether it was taken into account. Actually, I hope to ask all the relevant co-designers when I meet them in future conferences [relevant by my own personal secret criteria].
>
> Cheers,
>
>
>
> On Fri, Jul 31, 2026 at 5:36 PM Filippo Valsorda <filippo@ml.filippo.io> wrote:
>
>
> Excellent, sounds like you land at the same result as the chairs when tallying support by all participants. That’s promising!
>
> Then, have you tried tallying support by “pre-existing WG participants or people with demonstrated expertise” using your own methodology? Did you land at a result significantly different from “roughly 7/10”?
>
> Assuming you’re not looking a priori for something to object to, if you come to the same conclusion using your own methodology, I don’t see what good demanding an itemized list would do.
>
> If you do come to a significantly different result, you can share your methodology in your appeal, and let the ADs, IESG, or IAB assess it.
>
> 2026-07-31 15:55 GMT+02:00 Tanja Lange <tanja@hyperelliptic.org>:
>
> Dear Eliot, dear all,
> I can tally the emails on list, which were about even in favor and against.
> The chairs announced that by some process of discarding or weighing some votes
> they reach 70% in favor. To quote this verbatim
> "However, if we look at pre-existing WG
> participants or people with demonstrated expertise, roughly 7/10 WG
> participants favor advancing the document, which shows rough consensus
> to move the document forward."
> The requests I've seen, starting right after the chairs announced their
> decision that there was consensus in favor of the document, are asking for
> which input was discarded or counted higher or lower. I cannot do the
> "homework" of checking this because I don't know the mechanism used.
>
> Additionally, the email asking for responses was sent with
> Reply-To: Joseph Salowey <joe@salowey.net>
> so that replies would go to Joe's address and to the list only if the sender
> chooses to reply to all (or edits the header manually), so there might be some
> emails that didn't go to the list and which therefore I cannot count when doing
> my homework.
>
> Finally, there are reports of messages not appearing on list despite the
> sender responding with the release code. We have seen some messages containing
> release codes appear on list (I hadn't seen that in any previous discussion).
> My understanding is that the chairs see those, and maybe that's where the
> chairs saw additional support, but I cannot count these in my homework.
>
> Hence, I would like to support the request for transparency of how the 7/10
> (quoted above) was reached.
>
> All the best
> Tanja
>
> On Fri, Jul 31, 2026 at 01:02:26PM +0200, Eliot Lear wrote:
> > Hi,
> >
> > On 31.07.2026 12:37, Ken Kubota wrote:
> >
> >     There have been repeated requests [1, 2] that the working group chairs release the participant chart/list/table publicly that supports the 70 % claim ("7/10 WG participants favor advancing the document" [3]).
> >
> > Unnecessary.  All the information used by the chairs is publicly available on
> > this list.  Do your own homework.  Stop making work for others.
> >
> >
>
>
>
>
>
>
> > _______________________________________________
> > TLS mailing list -- tls@ietf.org
> > To unsubscribe send an email to tls-leave@ietf.org
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org