freenode
AnalysisSecurity & Cryptography

IETF TLS list: structural CoI question over Security AD meets moderation warning

A challenge to whether a long-career former NSA cryptographer can neutrally steward pure-ML-KEM standardization was answered mainly with character defenses and a chair's formal warning, not a structural debate.

On 16 July 2026, TLS working group co-chair Sean Turner posted a public moderation warning on the IETF TLS mailing list. The target was Andrew Lee, who had that same day pressed a structural conflict-of-interest question about Security Area Director Deb Cooley and the working group's last-call handling of draft-ietf-tls-mlkem-08, the pure ML-KEM key-exchange draft.

"This matter is resolved as far as the IESG is concerned," Turner wrote. "Continuing to raise this point here is a violation of CoC under BCP 94 / RFC 7154 and the mail list procedures that you agreed to when you joined this list. Consider this your public warning under BCP 25 and RFC 3954 and that continued posting on this topic will result in your posts being moderated."

Lee replied within minutes: "Thank you for proving my point. I said 'it will be impossible to trust Area Directors if structural concerns cannot be raised.' Alarmingly, you responded by threatening to moderate me for raising structural concerns."

The exchange did not settle whether the CoI framing was sound. It did settle, for the chairs and the IESG as Turner characterized them, that further pursuit of the point on the TLS list would be treated as a list-procedure problem. That collision (a structural process question answered first by character defense, then by moderation procedure) is the public-interest story. The internet's core security protocols still run through IETF process legitimacy.

What the last call was, and what an AD controls

Working Group Last Call on draft-ietf-tls-mlkem-08 ended 8 July 2026. The draft specifies pure ML-KEM for TLS, as distinct from hybrid constructions that combine a post-quantum KEM with classical elliptic-curve agreement. Objectors had argued that marking pure ML-KEM RECOMMENDED=N would not prevent implementation and use that could weaken real deployments, and that CNSA 2.0's preference for pure post-quantum algorithms aligned the desired outcome with an NSA roadmap. William Layton participated on-list as an NSA voice in that discussion; Ken Kubota and others tied the draft push to those interests.

Deb Cooley is Security Area Director on the IESG and a former long-career NSA cryptographer. On 10 July she refused recusal. "The topic of the working group last call is about a draft, not about NSA, I perceive no reason to recuse," she wrote. "I will also point out that I am retired from the US Federal Government, and I have no obligations to them, just like any other person changing companies wouldn't retain responsibilities of their previous company." On 15 July she added: "I have been a Security Area Director since March 2024, that is 2 years and a couple of months."

The formal powers of an Area Director are not unlimited, and they are not zero. RFC 9281 is the reference Lee and others invoked: an AD can assist a WG chair in assessing consensus; reviews documents after the WG has approved them; and when satisfied, coordinates IESG review and IETF Last Call. ADs also agree specific WG chairs under RFC 2418 and are consulted on moderation. Defenders stressed the other half of that picture. Watson Ladd put the strongest process counterpoint on 16 July: "Deb does not have influence over the TLS WG consensus, beyond sending in comments like anyone else. She's not tasked with determining what that consensus is, either: the WG chairs are."

That is the live tension. One side reads RFC 9281's assist-and-review role, plus chair selection and moderation consultation, as enough stewardship power that structural bias claims matter. The other side reads WG consensus as a chair function the AD does not own, so that prior employer history does not create a recusal duty on a document last call.

The structural challenge, and the character defense

Lee's 16 July framing tried to wall off personal attack. "The issue isn't whether or not Deb Cooley is a person of proper moral turpitude. Instead, it's whether a 37-year NSA veteran can serve as a neutral arbiter in a process where NSA employees are flooding the list in support, most of whom are participating for their first time, where NSA's CNSA 2.0 framework requires the exact outcome the NSA desires from this process."

Jacob Appelbaum, in parallel threads around 10 July, had also insisted the issue was process trust rather than character. He tied draft trust to RFC 7258's treatment of pervasive monitoring as an attack, and to published SIGINT Enabling and BULLRUN reporting on standards influence, including historical TLS-related operational material. He also pressed technical process points about ML-KEM's removal of Kyber's m <- H(m) pre-hash, arguing it destroyed a Dual_EC-shaped defense against hidden RNG structure; others, including John Mattsson, contested that technical reading and argued the right fix for broken RNGs sits outside the KEM. Those technical merits are adjacent context, not the governance question that later dominated the CoI thread.

Ken Kubota on 11 July pressed Cooley on disclosure and alleged uneven application of list warnings, linking the draft to NSA and CNSA interests and arguing that "the draft" and "NSA" were hard to separate given on-list participation patterns.

The dominant on-list response to the CoI thread was not a point-by-point structural analysis. It was a sustained defense of Cooley's integrity and of the IETF's ability to recruit ADs at all. Tim Hollebeek wrote: "These baseless accusations have no place at IETF. It's going to be impossible to find Area Directors in the future if this sort of behavior is deemed acceptable." Kathleen Moriarty: "I'm disappointed to read that any defense for Deb is even felt necessary." Hannes Tschofenig said he had found her "knowledgeable, fair, thoughtful" across working groups and was "puzzled that a statement of support like this is necessary at all." Dan Harkins, on 22 July, added: "These attacks and smears have no place in the IETF. Deb is a professional and has always acted with integrity."

Nico Williams offered the other strongest process counterargument, distinct from Ladd's institutional-roles point: "the horse left the barn two decades ago when the IETF decided to get out of fighting about national cryptographic standards, therefore Deb's 37 years at the NSA are irrelevant." On that view, re-litigating national-agency history on a TLS last-call list is a category error the IETF already exited.

John Mattsson argued suitability should have been an election-time issue, said prior NSA employment alone was not a CoI, compared the situation to algorithm designers not recusing on their own work, and expressed fear that Cooley might leave the IETF. Lee answered that concern directly: "I don't think whether or not someone will leave should be the determining factor on whether or not conflicts of interests should be ignored. That, in and of itself, is a conflict of interest."

Readers can weigh those positions without a scoreboard. Many long-standing participants clearly experienced the CoI framing as a smear that makes volunteer AD service impossible. The complainants clearly experienced the character chorus as a category mistake that never engaged the CNSA-alignment and arbiter-structure claim.

Moderation, a wrong RFC cite, and a fracturing list

Turner's 16 July warning initially cited "BCP 25 and RFC 3954." RFC 3954 is Cisco Systems NetFlow Services Export Version 9, a traffic-monitoring specification with no moderation content. Lee noted the mismatch: "The audacity of threatening moderation under a Cisco traffic monitoring specification, in a debate where Cisco employees are voting en bloc, is noted."

Turner corrected the same day. He restated the warning under BCP 25 and RFC 3934 (the actual IETF mailing-list moderation procedures) and repeated that the matter was resolved as far as the IESG was concerned, while saying objections could continue in the form Cooley's email had noted if they actually did so. The correction is a clerical fix; the substance of the warning remained.

Moderation pressure was not one-directional. On 17 July, Daniel Apon wrote: "I publicly request the TLS Chairs moderate Jacob's posts to the TLS mailing list if he can't focus on technical content in a professional manner in the future." Uri Blumenthal seconded. On 18 July, Nadim Kobeissi announced: "I am leaving the TLS list as a direct result of these ridiculous emails from Jacob." The list was fracturing on multiple axes: CoI process, historical SIGINT evidence boundaries, tone, and the pure-ML-KEM technical dispute itself.

Open process questions remain exactly where the thread left them. Whether a structural CoI claim about a former long-career NSA Security AD overseeing pure-ML-KEM may still be raised on the WG list after the IESG considers it resolved; whether BCP 25 / RFC 3934 moderation was the right governance tool versus further recusal or disclosure engagement; what public IESG CoI disclosure entries (Cooley's tabled as None/None across update dates) can and cannot say given national-security constraints; and where WG-list technical scope ends when process-trust arguments invoke documented standards-influence history. The chairs' posture is that the CoI point is closed for list purposes. The structural question the complainants named was never, on the public thread, given a structural answer of comparable length to the character defense.

Disclosure: Andrew Lee, quoted above, owns freenode, which publishes this site.