[Cryptography] NSA voting on TLS encryption at the IETF TLS WG

Andrew Lee andrew at joseon.com
Wed Jul 8 17:45:40 EDT 2026


Dear Rich,

> On Jul 8, 2026, at 12:46 PM, Salz, Rich via cryptography <cryptography at metzdowd.com> wrote:
> 
> 
> 
> On 7/8/26, 3:24 PM, "cryptography" <cryptography-bounces+rsalz=akamai.com at metzdowd.com> wrote:
> Example list of those opposing publication:
> ...
> Example list of those supporting publication:
> ...
> 
> Once again, Andrew unfairly summarizes to make his point.  Those who agree with him have their academic titles posted, those who don’t are smeared with things like “NSA Employee” as if we should a priori be scared of them. He couches them by saying “Example list” as if that adds credibility to their independence. This tactic becomes tiresome really quickly.
> 
> Why doesn’t the example list of those who support publication include
> Soatok, noted cryptographer (at laest on social media)
> Sophie Schmieg, noted cryptographer
> David Benjamin, world-class implementor of BoringSSL and others
> Scott Fluhrer, security developer/cryptographer
> Richard Barnes, co-author of various HPKE drafts (and the original ACME draft)
> John Mattson, security architect at Ericsson
> and so on.  (I would not put myself on that list, but I was a cypherpunk until the trolls took over, supported John Young regularly, and never worked for the NSA or Google.)
> 

Fair point. Let me fix it:

Example list of those against publication:
Ph.D Professor (co-creator of Ed25519, X25519, creator of chachapoly1305, etc. used by most)
Ph.D Professor (co-creator of Ed25519, X25519, former co-lead of EU PQ)
Ph.D (formal analysis author used in TLS WG FATT for this process)
Ph.D Professor (coauthored successful attacks on SHA-1)
Ph.D (team leader of EU PQ)
Ph.D (core Tor developer)

Example list of those in favor of publication: 
Dr. Sophie Schmieg (Google)
David Benjamin (Google) [1]
Scott Fluhrer (CISCO) [1]
Richard Barnes (CISCO) [1]
John Mattsson (Ericsson) [1]

[1] Could not find any verification on academic titles.

To help the in favor publication side, I refrained from putting NSA, GCHQ, Canadian Cyber Centre, etc., names.

> The job of the IETF if not to pick the best and only the best. It is our job to say “if you want to do XXX here is how to do it.” And best, particularly for security, often implies trade-offs such as message size, deployment difficult, overall operating environment, and so on.
> 

Do these trade-offs include RNG leakage?

Best,
Andrew

> 
> _______________________________________________
> The cryptography mailing list
> cryptography at metzdowd.com
> https://www.metzdowd.com/mailman/listinfo/cryptography

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://www.metzdowd.com/pipermail/cryptography/attachments/20260708/7b0c3a9b/attachment.htm>


More information about the cryptography mailing list