[TLS] Re: Improving the quality of the discussion on the TLS email list

Andrew Lee <andrew@joseon.com> Fri, 31 July 2026 18:50 UTC

Return-Path: <andrew@joseon.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 84C8E121D224D for <tls@mail2.ietf.org>; Fri, 31 Jul 2026 11:50:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785523847; bh=ZthUA1yspEsKvX5EZopnQggFF3tlhqY3/JxmP7BWTeM=; h=From:Subject:Date:In-Reply-To:Cc:To:References; b=igoElnvmh/RVRV8Ua1HbSh4Bd272kXSOBhGCbls5onajnkIFglJj+uL0voixFzvUa Eh280CywHUqzER19fWgm4HihfmWSo3SukcJfwr79O8BtqOFdw2jhG3KzVmVfBVkfFp zzvHkYixO0HjdeF8ZORtAcfu3RNk/XEV2WHqBXyo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=joseon-com.20251104.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6sDSmRYf2Es3 for <tls@mail2.ietf.org>; Fri, 31 Jul 2026 11:50:44 -0700 (PDT)
Received: from mail-pl1-x631.google.com (mail-pl1-x631.google.com [IPv6:2607:f8b0:4864:20::631]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id CE10E121D2242 for <tls@ietf.org>; Fri, 31 Jul 2026 11:50:44 -0700 (PDT)
Received: by mail-pl1-x631.google.com with SMTP id d9443c01a7336-2cc891373e0so14277235ad.2 for <tls@ietf.org>; Fri, 31 Jul 2026 11:50:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=joseon-com.20251104.gappssmtp.com; s=20251104; t=1785523844; x=1786128644; darn=ietf.org; h=references:to:cc:in-reply-to:date:subject:mime-version:content-type :message-id:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=8T4P++k5KD9KfGg3kaYEVbNx/HuMnfLqnshEEZDxxUM=; b=cI4uhdaT9UOYzhRX8uitHRFy1DIgOdDdm+fGZSKKTOGpBt6bNqTz0Uy3/9d3WlgtcO mubyQz6euWnJmcrIKeTvqtPgsm5TWzj9iUS/4DO7e2PfbGXgz4xUuS+wpfNaDTQ4huZB XoIFmIkAQ6PneVZIT2CPfjEdNR+56yqWMY6xL3FadYTzZ2UnZBzt3lvU0TjEpj4EAAmg QZMCXu59A6QSE8yAtkTnkPTUBZ0aIgcBMUHnPcO7cXvVIhwUk5oW8EsfuAhelo7jou+G X6oxa30t8h/2scpRBcFFsDZ/ZZPFV+9Qjmj7tWECKzxBqeoR6/CbYGyf5GBcbxM9FNVs hH9g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785523844; x=1786128644; h=references:to:cc:in-reply-to:date:subject:mime-version:content-type :message-id:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8T4P++k5KD9KfGg3kaYEVbNx/HuMnfLqnshEEZDxxUM=; b=MYqQcZhxcF0Q20NI2sB67QYcqlixy+TiPTbbyqT2uTsd6paskwZhYziJW5zcg4XGRl ZqPLPdYsklFIkdFh/6S9ZH9sxFwb6N3qxkwUXAOg/Yasju0hIlleJvLDxR1bn81K9hwo pAITlgc2GHbu/i0iqfoGtD4pkJL3vH24fhvSZuvpSjhonmXkhsqk1VS/7R2qcwLUi4Jb fUcKend7XTjS5LOi5lDWDcjjFMNctjOqIzyq3fmSG8xUyOdzc6Ry7gFW7QYkSqyVvHwq M2tt0qCC1okS1UZf0kO7lHS7VQh3MEjKVkVfiUj6eozFHUPpGR2yR/fDCNPOacMwGFtq Y2Og==
X-Forwarded-Encrypted: i=1; AHgh+RpF2B/K59hgF752fFu3Dl07W/ItiJVPT91L+Qf2CoVCXkWePVFz7lVxIwrghbE+tBdS864=@ietf.org
X-Gm-Message-State: AOJu0YzN8aGB/5h+FdeE4ttUqtIImgwndudE6KtwYASCTiVgs+WWl/7k kqXLKaEIeJRUV0l56b3SJ/k1syOiy3uWhmsyxIH7TthrSTtMWH9/UMlVTudTl0FAgTE=
X-Gm-Gg: AR+sD100+7XSthilVTiDzeVnFaAwcB6DSRWsgYHvN27Tg6OWD18V/9sn9c0zIeVFeez KZrXoMORMufum2+CBQBX97hMVvmT5sEqfhwmH4CbtRKsMfLrBkV+nJMlZ15KV6izw/5wudSpdK0 DNCmMmrzD4hmPtOy2v6zERlqECFOhw9i5LwV9voUlJVhyLdNXYcE2kONjlL0I7/IXicyVlultkj 4BEIAswuukUwvji2UEuxujwZ47iMBwostmLdMAeKxsGrdYpug//untKttkkvPyO6Kwq+Fw10K04 LLD/SEibduSKWxoDBn+JL5cxHT0bW1Bt/xcqnyvpeHgzVAgvaAnsjhA1KO2ep6aieFUWt6yOPJ3 FzduzUxG+L7ykiMMU8/kryXQdptRshM2R/hJi8N3nHs4XxeBd1jZangMh3zpSs4Y0cYN/pO0XHh Bm11ssQRstQKDgNcWPPG8Z1Yz3y0Y0DpYjKQkugXM7XpF+/CJLdHweKRfjfO1E/kS0znG/bCI95 iD3wyMKeAVJPyI+nCcLrtLZZIHh2ZM=
X-Received: by 2002:a05:6a21:1bc2:b0:3c3:abd4:ac74 with SMTP id adf61e73a8af0-3c92a8400eamr835119637.39.1785523843822; Fri, 31 Jul 2026 11:50:43 -0700 (PDT)
Received: from smtpclient.apple ([192.69.242.2]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153dd4e5c7sm9132485eec.5.2026.07.31.11.50.43 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 31 Jul 2026 11:50:43 -0700 (PDT)
From: Andrew Lee <andrew@joseon.com>
Message-Id: <0F869FB6-FAF9-4DBB-A046-3ABEA0A14C44@joseon.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_5C409BA2-ED4F-4D06-8E4B-8A8286B8575F"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3818.100.11.1.3\))
Date: Fri, 31 Jul 2026 11:50:32 -0700
In-Reply-To: <f5cb425b-6fd4-48f2-aec0-5272e9ff30fe@app.fastmail.com>
To: Filippo Valsorda <filippo@ml.filippo.io>
References: <CAEzBKQ4fymnSeo8tgqMLOfKopvMGk4xnDq=SQJKf-RBL4-uh6g@mail.gmail.com> <CAEEbLAbhZUpempA9Rvjhm1qrLfBWXa_2ntdfpO20cqDu0h5fbQ@mail.gmail.com> <CAEzBKQ6NOzQc66T+SEdSvLa2gxjtO77DYUUWuTfr99zV_a-Ofg@mail.gmail.com> <c8a74833-35cd-44a0-8992-e5463a82aa8f@dennis-jackson.uk> <F95592F7-6E60-4835-B21C-B5B1954084F7@kenkubota.de> <b3321e23-5f9b-4f8a-8bd9-d2cca2800d67@lear.ch> <amypaHNTh0Ya7XF+@ein.win.tue.nl> <538b6162-6cbb-4051-9810-601b29f880fe@app.fastmail.com> <CAA+_yBYWP_3MOcTM8FH8wjiif_L_WLOPVHKnp8nVmGJzFiCCpQ@mail.gmail.com> <f5cb425b-6fd4-48f2-aec0-5272e9ff30fe@app.fastmail.com>
X-Mailer: Apple Mail (2.3818.100.11.1.3)
Message-ID-Hash: ALHTSZOULFITU3QWGS66HCF6T63G6NHM
X-Message-ID-Hash: ALHTSZOULFITU3QWGS66HCF6T63G6NHM
X-MailFrom: andrew@joseon.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Orr Dunkelman <orrd@cs.haifa.ac.il>, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Improving the quality of the discussion on the TLS email list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/xLZ6nZF8aAVgXEU3ht87YbJ44zQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Dearest Filippo,

Suggesting that Dr. Lange and Dr. Dunkelman somehow reverse engineer the chairs' methodology is far from a serious response.

Nobody should have to guess at blackbox processes when it comes to the security of the billions of people on the internet. Further, an appeal cannot be conducted when the process which produced the outcome is unclear.

I'd like to remind everyone what happened during this Solo ML-KEM rough consensus determination exercise:

1. Not 1, not 2 but 3 WGLCs were conducted.
2. The AD issued statements about misrepresentation that occurred during one of the WGLCs.
3. Cleary, messages were both filtered and moderated.
4. The hero who won the people of the world the right to write, research and distribute cryptography was moderated from participating on the list during the process due to a common footnote that was, simultaneously, found and ignored from other participants.
5. This is already enough without having to mention the peculiarities relating to the sudden involvement from intelligence agencies.

Nobody is asking for an itemized vote list, Mr. Valsorda. However, I can understand why the distinguished PhD cryptographers on this list are concerned with the alarming conclusion to the rough consensus process... since we didn't hum [1], nor did we use a formal count to arrive at an outcome that contradicts what was suggested by nearly every discerning PhD and professor on the list.

So it's a pretty simple ask:

1. What counted as prior participation,
2. What counted as demonstrated domain expertise, AND
3. Were off list and moderated messages taken into consideration?

If the process was legit, it should cost nothing to be transparent.  That said, the continued refusal to provide these details is actively being written into history.

At best, this process looks Mickey Mouse... at worst, infiltrated.

Sincerely,
Andrew

[1] https://datatracker.ietf.org/doc/html/rfc7282

> On Jul 31, 2026, at 10:53 AM, Filippo Valsorda <filippo@ml.filippo.io> wrote:
> 
> Hi Orr,
> 
> Emphasis added:
> 
>> Then, have you tried tallying support by “pre-existing WG participants or people with demonstrated expertise” using your own methodology? Did you land at a result significantly different from “roughly 7/10”?
> 
> I have high confidence that Tanja, or you if you want to help, can give it a useful try.
> 
> 2026-07-31 19:10 GMT+02:00 Orr Dunkelman <orrd@cs.haifa.ac.il <mailto:orrd@cs.haifa.ac.il>>:
>> As the ADs did not publicly release the criteria relevant to what is considered "prior involvement" (would participation in one discussion before the ML-KEM sufficient to be considered in this set of voices?) nor what are the "experienced people" they deemed to be worthy of being heard (i.e., newcomers who are experienced), it is a bit impossible to make the statistics you have asked Tanja to make. Actually, even putting aside mailing issues, moderation problems, and assuming that indeed all the votes were indeed public, no one but the ADs can make these statistics. This is exactly what reasonable people asked for in this mailing list (including people from academia, industry and government) - to get these criteria publicly available. Hence, contacting IESG, IAB, the UN, or even the local fire brigade, is useless until the ADs supply this information. 
>> 
>> Furthermore, during the discussion I've pointed out that one of the co-designers of MLKEM found the idea of standardizing only MLKEM to be premature. I am sure that when assigning weights to participants, one of the guys inventing the thing (and especially as this particular individual has years of experience in industry, so this is not just a theoretical computer scientist with no understanding of the real world), should probably get a somewhat higher weight than even people who participated in past TLS discussions. As the ADs did not report counting this specific individual's "vote" (that says that the entire idea is bad) it is unclear whether it was taken into account. Actually, I hope to ask all the relevant co-designers when I meet them in future conferences [relevant by my own personal secret criteria].
>> 
>> Cheers,
>> 
>> 
>> 
>> On Fri, Jul 31, 2026 at 5:36 PM Filippo Valsorda <filippo@ml.filippo.io <mailto:filippo@ml.filippo.io>> wrote:
>> 
>> Excellent, sounds like you land at the same result as the chairs when tallying support by all participants. That’s promising!
>> 
>> Then, have you tried tallying support by “pre-existing WG participants or people with demonstrated expertise” using your own methodology? Did you land at a result significantly different from “roughly 7/10”?
>> 
>> Assuming you’re not looking a priori for something to object to, if you come to the same conclusion using your own methodology, I don’t see what good demanding an itemized list would do.
>> 
>> If you do come to a significantly different result, you can share your methodology in your appeal, and let the ADs, IESG, or IAB assess it.
>> 
>> 2026-07-31 15:55 GMT+02:00 Tanja Lange <tanja@hyperelliptic.org <mailto:tanja@hyperelliptic.org>>:
>>> Dear Eliot, dear all,
>>> I can tally the emails on list, which were about even in favor and against.
>>> The chairs announced that by some process of discarding or weighing some votes
>>> they reach 70% in favor. To quote this verbatim 
>>> "However, if we look at pre-existing WG                        
>>> participants or people with demonstrated expertise, roughly 7/10 WG                       
>>> participants favor advancing the document, which shows rough consensus                    
>>> to move the document forward."
>>> The requests I've seen, starting right after the chairs announced their
>>> decision that there was consensus in favor of the document, are asking for
>>> which input was discarded or counted higher or lower. I cannot do the
>>> "homework" of checking this because I don't know the mechanism used. 
>>> 
>>> Additionally, the email asking for responses was sent with
>>> Reply-To: Joseph Salowey <joe@salowey.net <mailto:joe@salowey.net>>
>>> so that replies would go to Joe's address and to the list only if the sender
>>> chooses to reply to all (or edits the header manually), so there might be some
>>> emails that didn't go to the list and which therefore I cannot count when doing
>>> my homework.
>>> 
>>> Finally, there are reports of messages not appearing on list despite the
>>> sender responding with the release code. We have seen some messages containing
>>> release codes appear on list (I hadn't seen that in any previous discussion).
>>> My understanding is that the chairs see those, and maybe that's where the
>>> chairs saw additional support, but I cannot count these in my homework.
>>> 
>>> Hence, I would like to support the request for transparency of how the 7/10
>>> (quoted above) was reached.
>>> 
>>> All the best
>>> Tanja
>>> 
>>> On Fri, Jul 31, 2026 at 01:02:26PM +0200, Eliot Lear wrote:
>>> > Hi,
>>> > 
>>> > On 31.07.2026 12:37, Ken Kubota wrote:
>>> > 
>>> >     There have been repeated requests [1, 2] that the working group chairs release the participant chart/list/table publicly that supports the 70 % claim ("7/10 WG participants favor advancing the document" [3]).
>>> > 
>>> > Unnecessary.  All the information used by the chairs is publicly available on
>>> > this list.  Do your own homework.  Stop making work for others.
>>> > 
>>> > 
>>> 
>>> 
>>> 
>>> 
>>> 
>>> 
>>> > _______________________________________________
>>> > TLS mailing list -- tls@ietf.org <mailto:tls@ietf.org>
>>> > To unsubscribe send an email to tls-leave@ietf.org <mailto:tls-leave@ietf.org>
>>> 
>>> _______________________________________________
>>> TLS mailing list -- tls@ietf.org <mailto:tls@ietf.org>
>>> To unsubscribe send an email to tls-leave@ietf.org <mailto:tls-leave@ietf.org>
>>> 
>> 
>> _______________________________________________
>> TLS mailing list -- tls@ietf.org <mailto:tls@ietf.org>
>> To unsubscribe send an email to tls-leave@ietf.org <mailto:tls-leave@ietf.org>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org