[Cryptography] NSA voting on TLS encryption at the IETF TLS WG

Peter Gutmann pgut001 at cs.auckland.ac.nz
Thu Jul 9 09:30:30 EDT 2026


Jon Callas <jon at callas.org> writes:

>The NSA does not vote. [...] The IETF operates by "rough consensus"

That may have been the case years ago but hasn't been that way for a long
time, depending on which WG you're looking at (there are probably some less-
interesting ones that still run the traditional way with rough consensus and
possibly even some running code).  The IETF votes (see the definition at
https://www.dictionary.com/browse/vote) even if you pretend really, really
hard that it's not voting by calling it something else, which is what all the
acrimony in the TLS WG has been over.  Both sides have attempted to stack the
vote in a manner that makes Microsoft's OOXML play look tame in comparison,
and then an IETF higher-up can step in and declare consensus whether there is
any or not and possibly contrary to the actual consensus, which has also been
an issue in the TLS WG.  It's turned into the biggest s**t show I've seen in
any working group I've taken part in, and I was involved with PKIX so that's
saying something.

For a longer breakdown of the problem, with supporting references and quotes
e.g. around voting, see "The Anatomy of a Dysfunctional Standards Body",
https://archive.openssl-conference.org/2025/presentations/Peter_Gutmann_ietf.pdf
(trigger warning if you contributed to the IETF back in the good old days).
Although that was written in early 2025, some of the "How to Fix This"
proposals actually address a lot of the issues that the TLS WG vote (sorry,
"looks like a vote, walks like a vote and quacks like a vote but absolutely
definitely isn't a vote") is currently facing.

And just for the record to avoid any conflict-of-interest appearance in regard
to the ML-KEM draft: I think it's a really bad idea to use it by itself but
also accept that it's probably going to get published anyway so don't plan to
lose any sleep over it.  Sometimes the only winning move is not to play.

Peter.


More information about the cryptography mailing list