What Happened

, I minions had called and were packing standardizing a specification remove the ECC seatbelt from hybrid ECC+ML-. For example, 's Mike Jenkins, mailing list before. I responded by calling for volunteers public-interest side.

I'm happy to report that 82 people mailing list in unambiguous opposition during the voting period. additional people (Izzy Grosof, for example, and Ivan Visconti) who had already registered opposition before the voting period; I've heard credible reports of further opposition messages being blocked by the chairs; and, even though this wasn't filed as opposition, following statement from Roberto Avanzi: "as a codesigner of ML-KEM myself I exclusively: broken mathematically classical computational model (I.e. non-quantum)? Hybrid is better, and the additional significant."

(In the opposite direction, I've been pointed to the following claim from Thomas Ptacek: "The more cryptography-literate you are, the more likely hybrids are silly." Oh, well, I guess that settles it then.)

For 75 of the 82 people with opposition statements during this voting period, I anyone arguing that anything in their messages suggests the possibility of spec modifications removing the objections. I've taken quotes from those 75 people and forwarded them to "IESG", the Internet Engineering Steering Group, replies to talking points from spec proponents. Copies of my messages to IESG: 1, 2, 3, 4.

Why It Matters

's supposed to happen, what has happened so far, and what's likely to happen next.

Here's : "IETF participation interested individuals. ... IETF activities are conducted with extreme transparency, in public forums. Decision-making requires achieving broad consensus via these public processes. ... Fundamentally, 'IETF participants engineering judgment solution Internet, solution for any particular network, technology, vendor, or user.' "

divided across "working groups" (WGs). Here's decisions: "The general Working Groups make decisions Working 'rough consensus', meaning that a very large majority , minority have had a chance to explain points have been addressed, agreed with."

There's a further rule that "51% of the working qualify as 'rough consensus' ". 't say "51% of a quorum". Also, there's a rule that disagreements "must be resolved by a process of open review and discussion".

What Comes Next

If a WG "last call" shows "rough consensus" , 't directly. Instead forwards , which issues its own "last call". "Comments on a Last- accepted from anyone". If IESG decides , "represents the consensus community".

't "rough consensus" —for example, 't reached agreement of "a very large majority "—'t supposed ; it's supposed to be rejected chairs.

For this particular spec, -packing "vendors", proponents certainly don't have 51% of the working group—and 51% still wouldn't qualify. Proponents certainly don't have "a very large majority" of the people who cared enough ; they weren't people . Furthermore, the most important points from opponents remain unaddressed.

To summarize, "rough consensus" includes a bunch of requirements 't meet. chairs were supposed to say: sorry, there isn't "rough consensus" .

The chairs ignored declared "rough consensus" . shifting rationales they've presented :

Story 1: "-existing WG participants or people with demonstrated expertise, roughly 7/10 WG participants favor advancing the document, consensus document forward". (Where's people that the chairs declare haven't "demonstrated expertise"? What happened to "IETF participation interested individuals"? What happened to "Decision-making requires achieving broad consensus via these public processes"? What happened to reaching agreement of "a very large majority "?)

Story 2: the chairs "focused their consensus judgement on people that participated ". (Wait, so new participants with "demonstrated expertise" suddenly don't ? chairs disenfranchise new participants -existing participants?)

Explore more: Software & AI Guide