freenode
AnalysisSecurity & Cryptography

Bernstein files a formal complaint against SSH chairs who tried to silence him

The SSHM chairs met an unanswered objection to solo post-quantum signatures with moderation threats instead of discussion. D. J. Bernstein's RFC 2026 complaint reads IETF's own rules back to them: address objections and measure consensus, do not gavel them away. The call for adoption closes 17 August.

When you cannot answer the argument, gavel the arguer

The IETF's Secure Shell Maintenance working group could not answer D. J. Bernstein's objection to solo post-quantum signatures, so its chairs tried to end the conversation instead. On 28 July 2026, after a week of being told to stop talking, Bernstein filed a formal complaint. "This is a complaint to the chairs under RFC 2026, Section 6.5, regarding their violations of a variety of IETF promises quoted below regarding participation and consensus," it began. Co-chair Job Snijders replied within hours: "Sorry to hear you have a complaint about the chair team. We'll get back to you in the next few days."

The complaint did not come out of nowhere. The working group is deciding whether to standardize solo ML-DSA for SSH authentication or to require hybrids that keep a classical algorithm such as Ed25519 alongside the post-quantum one, and the case for hybrids, covered here previously, is strong and has gone unrebutted on the merits. A signature that can be forged because of a single ML-DSA implementation bug is a live credential in an attacker's hands, and an Ed25519 layer that removes that risk costs almost nothing. Rather than answer that argument, the chairs decided they had heard enough of it.

The censorship, in the chairs' own words

The record is not ambiguous, because the chairs put it in writing. As the discussion of solo post-quantum risk continued, chair Stephen Farrell moved to shut it down. "IMO, there's no new information below, people have already gotten sufficient information to enable them to make up their own minds," he wrote, telling Bernstein to "desist from further repetitive postings on this sub-topic." When Dmitry Belyavsky raised a regulatory point, Farrell dismissed it too: "that point has also been made, repeatedly." To John Mattsson he offered only "#include :-)". A working group chair is supposed to collect the discussion the rules require. This one was busy closing it.

Then came the threat. After Bernstein spelled out a real and specific distinction between two risk assessments, Farrell did not engage with it. "People are well aware of the above and have their own opinions on the matter, not all of which are the same as yours. Some agree with you, some don't. That's life," he wrote, and then: "This is your last warning - continuing to discuss this sub-topic in the absence of new information means I'll moderate your postings. (Holding them 'till I've seen if they have new material or not.)" If it came to it, he added, "I'll figure out what mailman buttons need hitting."

That is a chair with an opinion on the outcome threatening to intercept the messages of the participant making the opposing case. Bernstein named it for what it was: "This is a perfect example of how wrong it is for the chairs to be systematically disrupting discussions in favor of 30-second ads," pointing to the rule the chairs were trampling, that "RFC 2418 says that disagreements 'must be resolved by a process of open review and discussion'."

The complaint is right on the rules

Strip away the personalities and Bernstein's complaint is simply IETF's own rulebook read back to the people who are supposed to enforce it. He quotes the IETF process page: a working group must reach "rough consensus," meaning "a very large majority of those who care must agree, and that those in the minority have had a chance to explain why and their points have been addressed." He quotes RFC 2418 that 51 percent does not qualify as rough consensus, that disagreements "must be resolved by a process of open review and discussion," and that "wide participation is encouraged." None of that is Bernstein's invention. It is the standard the chairs signed up to apply.

Measured against it, the chairs are failing on their own terms. They are suppressing participation rather than encouraging it: from the opening of the call, Farrell announced that "we will not be paying much attention to people who show up afresh just for this call for adoption and who do not make new technical arguments," which, as Bernstein notes, "actively corrupts the evaluation of whether 'a very large majority of those who care' agree." The people being waved off are not cranks. "More than 80 people on the TLS mailing list objected to solo ML-KEM in TLS," he points out, "typically with rationales that also apply to solo ML-DSA in SSH." His question deserves a straight answer the chairs have not given: "For the record, do the chairs understand that solo PQ is controversial?"

They are also refusing to resolve objections through discussion and instead declaring the matter closed. As the complaint puts it, the chairs met a live technical dispute with "Some agree with you, some don't" and "threatened immediate censorship in response to any further discussion of the topic," which "is exactly the opposite of what RFC 2418 says." And most damningly, they justified the whole exercise with a claim of agreement that Bernstein says never happened. The call for adoption was announced on the basis that "the WG agreed to do a call for adoption for PQ sigs using ECC and ML-DSA," yet, he writes, that framing "ignored the fact that there were already unresolved technical objections on list to solo PQ in SSH," and the "WG agreed" claim itself "seems to be false." A chair's job is to determine consensus, not to conjure it. As Bernstein puts it, the role is not "an assignment of authority for Humpty Dumpty to declare 'rough consensus means just what I choose it to mean'."

The excuse does not hold

The chairs will say they are only protecting a three-week call from endless re-litigation, and their allies cheer it on; John Mattsson thanked them "for making it very clear that they will not let SSHM become another TLS." It is a tidy line, and it does not survive contact with the record. "Repetition" is the label the chairs apply to an objection they have not answered. There is nothing circular about asking whether a signature scheme with no classical fallback is safe to standardize, and there is nothing new the chairs have said to close it; they have simply decided that continuing to raise it is a moderation offense. A rule that says objections "must be resolved by a process of open review and discussion" is not satisfied by a chair announcing that discussion is over. If the point had truly been answered, no mailman buttons would be needed.

There is a reason Bernstein now appends a legal notice to every message, invoking his rights under BCP 78, opting out of any modification of his contributions and objecting to "IETF management selling IETF mailing-list text to AI companies" while remaining "fine with redistribution" and "quotes for purposes of commentary." This is a participant who no longer trusts the institution to represent him fairly, and the handling of this call is a case study in why.

The complaint is now in the chairs' hands, and their own leadership has promised an answer within days. That answer should not be another word about repetition. Before they adopt anything ahead of the 17 August deadline, the chairs owe the working group a demonstration that they followed the rules IETF actually promises: that objections were addressed rather than gaveled away, and that consensus was measured rather than declared. On the evidence so far, they cannot make that showing, which is precisely why the drafts should not proceed until they can.