freenode
AnalysisSecurity & Cryptography

Moderated over a footnote: Bernstein, pure ML-KEM, and the IETF's closed door

While the TLS working group pushed pure ML-KEM through last call, chairs repeatedly silenced the draft's most rigorous critic over a copyright protest footnote, as signals-intelligence participation went largely unexamined.

On 29 June 2026, with the TLS working group's last call on draft-ietf-tls-mlkem-08 already under way, Security Area Director Deb Cooley stated the grounds for silencing one of the world's most important cryptographers in the plainest possible terms. "He is not being moderated for the technical content, but for the footnote which contains a derivative rights statement. If he would merely post messages without this statement, they would be sent to the list."

The "he" was D. J. Bernstein. The draft under last call specified pure, non-hybrid ML-KEM for TLS: post-quantum key establishment without the classical elliptic-curve safety belt that hybrid designs retain. Bernstein had been the field's most persistent technical objector to that design choice. The stated price of his continued participation, at the exact moment the working group was taking its decisive vote, was that he drop a copyright-protest footnote from his mail.

That disproportion is the story. A process that repeatedly moderated Bernstein over a derivative-works notice, narrowed or deflected his appeals, and closed the very venue the IAB told him to use, did so while a draft making a contested safety property optional advanced under heavy participation from NSA, allied signals-intelligence agencies, and defense contractors. The chairs' stated rationale does not survive contact with the chronology. The accountability questions the record raises have received far less scrutiny than they deserve.

A footnote as a gate

The pattern did not begin in June. On 17 October 2025, TLS chair Joseph Salowey "decided to moderate the postings of D. J. Bernstein for 30 days due to disruptive behavior ... under BCP9 / RFC3934 Section 2, with the exception that moderation instead of suspension of all posting rights is applied." On 26 November 2025, Cooley, then acting in a SAAG chair capacity, moderated him again "for 30 days due to continued disruptive behavior as allowed by the IESG statement on the intentional inclusion of a derivative works in list emails."

By April 2026 the list was openly debating whether the remedy should be permanent. David Adrian wrote that he believed "the chairs should permanently ban Dan from the list under RFC 9945, and that the IAB or IESG should follow-on by banning Dan from all IETF mailing lists and meetings." Others saw something else. Nico Williams, surveying the same fight, treated the footnote as protest rather than sabotage: "footnotes that complain about such rules are perfectly reasonable. Yes they are noisy protests, but so what?" His advice to the chairs was to ignore the footer. Rick Wesson urged against censure and preferred "levity and tolerance" while difficult consensus work continued.

Nadim Kobeissi, who has often disagreed with Bernstein on technical points, described the disproportion in blunt terms. After listing unmoderated personal attacks and mockery on the same list, he wrote: "The TLS Chairs are unbelievably biased and obviously incompetent." Cooley answered with a public RFC 3934 warning. Kobeissi accepted it, then returned with a more careful assessment: Bernstein was verbose and repetitive, some of his talking points unconvincing, yet "the vast majority of his contributions are indeed technical points" and he was being treated "like he's some kind of bogeyman." "He's just a difficult and highly opinionated person. He's just a passionate mathematician. He's largely technical."

On or about 28 June 2026, during the working-group last call on draft-ietf-tls-mlkem-08, the TLS chairs again placed Bernstein under 30-day moderation. Messages would require chair approval and could be delayed up to two business days. The last call was scheduled to end 8 July. Cooley's clarification the next day left no ambiguity: the gate was the footnote, not the cryptography.

Andrew Lee, filing an independent appeal under RFC 9945 Section 4.1, noted that this was "the Nth time" Bernstein had been moderated over a copyright notice. He also challenged the cited authority. RFC 3934, he wrote, was listed as obsoleted by RFC 9945; the moderation notice's citation of BCP 9 (RFC 2026) rather than the operative text was "wrong on its face." Whether the chairs' legal footing was sound became a secondary dispute. The practical effect was not.

Appeals that pointed nowhere

On 30 June 2026 the IAB denied Bernstein's appeal on draft-ietf-tls-mlkem. In the same breath it told him where technical objections belonged: in the working group's ongoing process, "including Working Group Last Call." Lee's appeal put the contradiction in italics. "The IAB told Dr. Bernstein to make his case during WGLC. The chairs are preventing him from doing so. These two actions directly contradict each other."

Lee asked the full IESG to handle the matter because, in his view, neither Security AD could serve as a neutral adjudicator. Cooley had already stated on-list, "I have seen no bias from my chairs," and had instructed a participant not to raise chair bias again. The other AD history Lee recited included prior recusal. He argued the situation was functionally one in which the responsible AD "cannot be determined or is not assigned" under RFC 9945 Section 4.1.

IAB Chair Dhruv Dhody, speaking personally on 2 July, clarified the IAB's language: WGLC was the venue for technical objections, operating under normal moderation rules; an earlier AD characterization of an adoption call had been imprecise and later corrected. Lee accepted the wording fix and returned to the operational point. Whether moderation was "theoretically permissible" did not resolve whether it was "compatible with the IAB's own guidance" during a time-limited last call.

Parallel threads in the archive carry titles that read like a process closing in on itself: Form of Appeals, Complaint to IAB regarding non-transparent handling, Scope of the IAB appeal response, Complaint regarding IESG removing an appeal process. Eric Rescorla urged that moderation disputes go through RFC 2026 appeals rather than on-list relitigation. That advice assumes the appeal path is open, timely, and capable of relieving a silence imposed during a vote that ends in days. The record available through early July does not show such relief arriving in time for Bernstein's full participation in the last call.

Sam Leavin, as the last call ended on 8 July, still wrote: "I reiterate that I do not support the publication of this document." He asked for patience and for something closer to a tracked issues list so that grievances were visibly addressed. The document, he noted, "could affect millions of people for decades to come." The most prominent technical critic had spent the decisive window under moderation for a footnote.

What the draft actually risked

The technical stakes can be stated briefly. Draft-ietf-tls-mlkem-08 specifies pure ML-KEM for TLS. Hybrid constructions (ML-KEM combined with elliptic-curve key exchange) are framed by critics as defense-in-depth against immature post-quantum algorithms; the 2022 break of SIKE, a NIST finalist, is the usual exhibit that PQC can fail quickly. RFC 9958, published in June 2026, itself records uncertainty about underlying mathematics, compliance, unknown vulnerabilities, and immature implementations. Opponents of the pure draft argue that marking the code point RECOMMENDED=N is not enough: if both endpoints offer pure ML-KEM, code will ship and the weaker choice can be selected. Supporters answer that telecom and other industries need an RFC for procurement, that CNSA 2.0 and FIPS demand pure PQ for some U.S. government buyers, and that the draft specifies a method rather than anointing a default.

Uri Blumenthal of MIT Lincoln Laboratory put the supporters' confidence bluntly on 3 July: "There is some disagreement, but the credible cryptographers - except one - do support the publication." The "except one" needed no introduction. Soatok Dreamseeker argued the RFC was needed for FIPS and CNSA 2.0 compliance, not as a NOBUS backdoor, and warned against fractured-SDO outcomes of the SPECK-via-ISO kind. John Preuß Mattsson of Ericsson defended the standards context and repeatedly tried to wall historical SIGINT subversion off from the current TLS debate.

A second technical flashpoint ran in parallel: the removal of the Kyber/ML-KEM m <- H(m) hashing step in FIPS 203. Jacob Appelbaum argued that the removal fails to destroy Dual_EC-like hidden structure and leaves a problem when ML-KEM is composed with TLS. "Refusal to address the technical issue of destroying any possible hidden structure is the issue. My core concern has nothing to do with entropy." Mattsson replied that the step neither adds entropy nor fixes a fully controlled RNG, that the removal was proposed by a European cryptographer, and that the correct fix is better RNG outside ML-KEM. Appelbaum also noted that Blumenthal had earlier, on the NIST PQC forum, supported keeping the hash as defense-in-depth, then stopped arguing after NIST's decision. None of this was resolved by last-call day. It was, however, the kind of argument Bernstein had been built to force into the open.

The room and the unaddressed questions

Participation is not the same as support, and the archive does not show every government or contractor participant arguing for pure ML-KEM. It does show an unusual density of signals-intelligence and defense-contractor addresses in the ML-KEM and consensus threads, and it shows critics treating that density as an unaddressed conflict of interest.

From NSA domains the record names Rebecca Guthrie (uwe.nsa.gov), Morgan B. Stern (nsa.gov), William Layton (cyber.nsa.gov), and M. Jenkins (cyber.nsa.gov). From GCHQ/NCSC-UK (ncsc.gov.uk): Flo D, Matt G, Michael P, and Peter C. From CSE Canada: Jonathan Hammell (cyber.gc.ca). From defense contractors: Anthony Barnett and Beatrice Peirani-Mercelot of Thales, and Uri Blumenthal of MIT Lincoln Laboratory. William Layton was among those Ken Kubota addressed directly in the hybrid and safety-belt debate. Morgan Stern appears in FOIA and track-changes discussion, as Appelbaum presented it, as "Morgan of NSA" commenting on NIST PQC drafts. Blumenthal, as noted, publicly supported publication of the pure-ML-KEM draft.

Kubota stated the structural complaint without hedging: "the presence of a double-digit number of identified intelligence agency operatives from the NSA, GCHQ, and CSE, the resulting conflict of interest, and their uniform voting behavior remain completely unaddressed." He tied the pure-ML-KEM push, the SIKE lesson, and the m <- H(m) removal to a longer pattern that includes Dual_EC_DRBG. On 10-11 July he pressed Cooley on recusal and on what he described as selective enforcement of conduct rules.

Cooley declined. "The topic of the working group last call is about a draft, not about NSA, I perceive no reason to recuse." She added: "I will also point out that I am retired from the US Federal Government, and I have no obligations to them, just like any other person changing companies wouldn't retain responsibilities of their previous company." Appelbaum, citing her IETF biography's account of a major career stretch at NSA IAD/CSD, answered that the issue was "not personal" but "trust in a standards process." He quoted RFC 7258: "To summarise: current capabilities permit some actors to monitor content and metadata across the Internet at a scale never before seen. This pervasive monitoring is an attack on Internet privacy. The IETF will strive to produce specifications that mitigate pervasive monitoring attacks." He laid out the BULLRUN record, DER SPIEGEL reporting on NSA attendance at IETF meetings "to gather information but presumably also to influence the discussions there," and FOIA material that, in his account, complicates NIST's public narrative of limited NSA authorship on PQC drafts.

Mattsson granted the historical premise while denying the present link: "The fact that SIGINT agencies have systematically weakened standards to facilitate interception is a fact, but it has very little to do with TLS." Appelbaum replied that BULLRUN material specifically discusses TLS/SSL workflows at scale and that the relevance fight could not be won by assertion. Eliot Lear called parts of the exchange "HIGHLY inappropriate." Appelbaum disagreed: "Bringing current and former NSA people onboard into the IETF leadership presents unique challenges. The IETF should be leading with transparency and openness."

These are attributed claims and documented precedents, not courtroom findings. Dual_EC_DRBG happened. BULLRUN happened. RFC 7258 exists because pervasive monitoring is an attack. FOIA track-changes naming NSA technical comments on NIST PQC drafts exist in the critics' presentation of the record. Kubota's "uniform voting behavior" claim is an on-list allegation that the process has not publicly audited. Cooley's refusal to recuse rests on a bright-line claim that the last call is "about a draft, not about NSA" and on her retirement. Reasonable participants can weigh those answers differently. What the process has not done is weigh them with the seriousness the precedents demand while the most relentless technical objector was on moderated status for a footnote.

Why the footnote story is the governance story

Chairs and ADs have a stated rationale: derivative-works notices in list mail violate an IESG statement; repeated inclusion is "disruptive behavior"; moderation short of full suspension is the measured response; anyone may post freely by omitting the notice. On its own page that account is tidy.

Set beside the calendar it is not. Bernstein was moderated in October 2025, November 2025, and again on 28 June 2026 as draft-ietf-tls-mlkem-08 entered its final last-call week. The IAB, denying his document appeal, directed technical objections into that same WGLC. The chairs' moderation, by Cooley's explicit admission, turned on the footnote and would lift if he stopped protesting copyright terms. Lee's RFC 9945 appeal called the contradiction by name. Voices on the list, including Williams, Kobeissi, and Wesson, read the enforcement as selective protest-policing rather than neutral disruption control, especially against a backdrop of unmoderated personal attacks. Authority citations themselves were contested under the RFC 3934 / RFC 9945 transition.

Meanwhile a safety property (hybrid defense-in-depth against a still-young PQC primitive) was being made optional in an IETF TLS specification. The field's most prominent critic of that choice was under a posting gate. The room included a double-digit identified contingent from NSA, GCHQ, CSE, and aligned defense contractors, whose collective presence and, in Kubota's allegation, voting pattern the process treated as ordinary participation. The Area Director overseeing security, a former NSA IAD/CSD official, declined to recuse because the topic was "a draft, not about NSA."

None of that proves a backdoor in ML-KEM. It does not need to. Governance failures are measured by whether a standards body can still hear its most informed dissent when institutional incentives, procurement pressure, and historical SIGINT interest all lean one way. Moderating Bernstein over a copyright footnote, repeatedly, exactly through the decisive last call, functioned to remove the most rigorous objector at the moment it mattered most. The appeals path talked past that fact or arrived too late to cure it. The agency-presence questions were met with process points and recusal refusals rather than transparent accounting.

The IETF has survived hard cryptography fights before. It has also, in living memory, had to write RFC 7258 because large-scale monitoring is an attack, and it has had to live with Dual_EC as a permanent exhibit of what captured standards work can cost. Pure ML-KEM in TLS may or may not be the right engineering choice; that argument deserved Bernstein at full voice. What it received instead was a moderated queue, a footnote ultimatum, and a process that still has not explained, with anything like adequate seriousness, why that was acceptable.


Disclosure: Andrew Lee, named above as an appellant, owns freenode, which publishes this site.