Markdown Version | Transcript | Session Recording | Session Materials
HRPC
Summary
The Human Rights Protocol Considerations (HRPC) Research Group met at IETF 126. The session was chaired by Mallory Knodel, with Laura acting as the note-taker.
The meeting featured two primary presentations:
- Corinne Cath presented research on "CloudRift," exploring how the migration of internet governance organizations to commercial hyperscale cloud networks impacts their public interest missions and technical decentralization.
- Tim Engelhardt from the Office of the UN High Commissioner for Human Rights (OHCHR) provided an update on technical standards and human rights, highlighting key insights from recent global consultations and upcoming institutional initiatives at the ITU-T.
The session concluded with a discussion on how the HRPC community can better engage the broader IETF to translate human rights considerations into protocol design.
Key Discussion Points
Administrative and Draft Status Updates
- Chair's Welcome: Mallory Knodel opened the session and presented the Chair's Welcome Slides. She noted that co-chair Sofia Celi was unable to attend due to flight issues but would present her measurement work at IETF 127 in November.
- Active Work: The research group has two active areas of interest: a draft on freedom of association and a draft on intimate partner violence considerations.
- Chat Discussion: Mallory Knodel shared a link to an older draft, draft-irtf-hrpc-political-06, during a discussion about internet governance politics.
CloudRift: The Impact of Hyperscale Cloud on Internet Governance Organizations
Corinne Cath presented her research on "CloudRift" using Corinne’s slides.
- The CloudRift Concept: The research investigates the institutional changes that occur when internet governance organizations (specifically those with public interest mandates) become dependent on commercial hyperscale cloud providers.
- The SIDN Case Study: The paper analyzed the Dutch top-level domain registry (.nl) manager, SIDN, and its announced migration of parts of its operations to Amazon Web Services (AWS) in early 2024. This move sparked intense public and parliamentary debate in the Netherlands, leading to a temporary halt of the migration.
- Key Observations:
- Expertise Shift: Internal engineering expertise often transitions from full-stack technical knowledge to vendor management (e.g., AWS-specific training).
- Priority Alignment: Organizational priorities shift to align with the commercial provider's technical and business architecture.
- Erosion of Public Mission: Corporate values are slowly absorbed, hollowing out public interest priorities (such as defending a decentralized internet topology).
- Q&A and Discussion:
- Lars Eggert asked whether the core issue is outsourcing infrastructure broadly (infrastructure-as-a-service) or specifically outsourcing to non-European (principally US-based) entities. Corinne Cath clarified that the primary concern is the "capture of operations" by commercial entities that forces standardization based on the provider's business model, regardless of whether the provider is US- or EU-based.
- Tara Tarakiyee asked what architectural or open-standard levers are available to resist this consolidation. Corinne Cath responded that while standardizing is hard when only big corporations run the infrastructure, the community must focus on building viable "transition infrastructures" (alternative, decentralized solutions).
- Kurtis Heimerl asked if this centralization is cyclical (citing Tim Wu’s The Master Switch). Corinne Cath argued that it is foundational and structural rather than cyclical, due to the financial changes involved (e.g., writing off capital expenditure in favor of operational cloud budgets makes reversing the migration highly difficult for public institutions).
- Colin Perkins questioned whether governance organizations are simply evolving to reflect the highly centralized reality of the modern internet. Corinne Cath countered that technical design is political rather than a "natural evolution," meaning alternatives can and should still be actively constructed.
- Chat Contributions:
- Alexandr Railean and Andrew Campling noted that cost-efficiency and DDoS/attack resistance make hyperscalers highly attractive to subscale registries.
- Stephen Farrell pointed out that universities similarly outsource to hyperscalers because they cannot compete with industry salaries to retain in-house systems administrators.
- Ted Lemon noted that email spam remains an unsolved operational burden because the community has struggled to agree on protocols capable of automatically rejecting spam at a low cost.
- Avri Doria noted that the UN Guiding Principles on Business and Human Rights (originally published in 2011/2012) is in need of an update to address contemporary cloud-era challenges.
Technical Standards and Human Rights: OHCHR Update
Tim Engelhardt presented on behalf of the OHCHR, referencing the OHCHR presentation Technical standards and human rights.
- Global Developments: The intersection of human rights and technical standards is gaining significant visibility. Mention was made of the UN Global Digital Compact (GDC), WSIS+20 documents, and a joint statement from ISO, IEC, and ITU highlighting the need to integrate human rights and socio-technical lenses into standards development.
- Consultation Findings: The OHCHR published a follow-up report in late 2023 identifying three major areas of focus:
- Inclusive Participation: Addressing financial and structural barriers that prevent civil society, small-to-medium enterprises, and the global majority from participating in SDOs.
- Institutional & Procedural Design: Recommending structural reforms, such as human rights focal points in SDOs, and the introduction of Human Rights Due Diligence (HRDD) checklists.
- Multi-stakeholder Collaboration: Encouraging knowledge-sharing and research partnerships to prevent duplicate efforts.
- ITU-T Human Rights Checklist: Tim Engelhardt shared that a group of ITU-T member states recently submitted a proposal (with OHCHR support) for a human rights checklist to the Rapporteur Group on working methods as part of the TSAG process.
- Q&A and Discussion:
- Mallory Knodel asked if the proposed ITU-T checklist is publicly available. Tim Engelhardt indicated it is an official contribution and recommended coordinating bilaterally to share details. Lars Eggert added that because the IETF and ITU-T have a standing materials-sharing agreement, IETF/IRTF participants should be able to access the document.
- Tara Tarakiyee asked how Economic, Social, and Cultural Rights (ESCR) can be integrated into standards without being relegated to a mere "development" lens. Tim Engelhardt agreed that isolating ESCR to development limits its human rights impact and noted that while complex, its integration is vital. Mallory Knodel added that in her experience, ESCR arguments (such as in age-verification protocols) are often more persuasive to implementers than civil/political rights arguments.
- Andrew Campling highlighted the ITU-T's work on "Child Online Protection" as an encouraging sign of an SDO willing to tackle difficult human rights issues that the IETF has historically struggled to address.
- Simone Onofri reported that the W3C is currently translating the OHCHR report's framework into its own processes. He asked about the technical trade-offs between privacy/security and child protection. Tim Engelhardt emphasized that framing this as the "rights of the child" puts children's agency at the center, helping to navigate the complex trade-offs more holistically.
- Carolina Caeiro raised a question about how the HRPC can move past "preaching to the choir" and effectively engage the wider IETF on concrete procedural mechanisms and protocol design considerations.
Next Steps
- Mailing List Discussion: Mallory Knodel and Carolina Caeiro will initiate a thread on the HRPC mailing list to gather ideas on how the research group can more effectively engage the broader IETF on protocol-level human rights considerations.
- Document Access: Follow up on obtaining and sharing the ITU-T human rights checklist contribution through existing IETF/ITU-T sharing agreements.