It’s important to point out that this was NOT an official
IETF event, and neither was it giving external advocacy
organisations a stage (as some have intimated); rather,
it was entirely an effort of individuals, working within
the rules for requesting a room at IETF meetings.
I do not recognize the significance of "official" versus "unofficial" IETF events. I don't think there's a meaningful distinction to be made between them. Anyone in the world can show up to an "official" event, or participate in the mailing lists. That's a good thing, but it also means that "unofficial" advocacy and advice is as important as the "official" kind.
The real point is that no advice or consultation was being made, it was purely opinion-based commentary. There is no reason to believe it will affect WG charter, and in fact The Tao of IETF explicitly notes that face-to-face WG meetings aren't of high significance to the actual WG's charter. Snowden recommending DNSSEC isn't going to suddenly suspend all rational judgment in those circles.
If you spend some quality time reading IETF mailing lists, you'll learn that it's all "opinion-based commentary". I'm a little confused as to what your argument here is. The IETF works by means of people persuading other people to support proposals. That's the entire mechanism.
I wouldn't say that Snowden was intending to provide technical (or specifically cryptographic) advice in this Q&A. I would compare it to a power user giving feedback to the engineers working on improving their software.
What he brings to the table in discussions like this is basically having worked with people on surveillance projects. He knows how they operate and where they'd look for attack vectors. I think that's valuable when you have to think about designing any system with any kind of security requirements.
He literally stated himself that what he says shouldn't be accepted as gospel, and in a later question about MITM specifically confirmed that it's not his area of expertise. I don't think there's any risk of people suddenly jumping on the DNSSEC bandwagon just because of his lukewarm support.
His support isn't lukewarm. Also: now, when DNSSEC is almost dead, is the most important time to ensure that it actually becomes fully dead. It's like a zombie. You have to cut off the head and burn the body. DNSSEC is still intact and twitching.
I wouldn't classify statements like "we gotta start somewhere and then we've got to iterate from that point" or "It's better than what we have today" as a call to action to drop everything and start implementing DNSSEC as-is right away. I would interpret it as "yes, DNSSEC improves the situation in that it provides authenticated DNS replies (which - by itself - is an improvement, even though it's no magic wand that, alone, solves the cert trust issue), but there are legitimate concerns that need to be taken care of before it becomes really useful."
"DNSSEC improves the situation" is (a) false and (b) a concession to the narrative that DNSSEC is worth doing.
Someone actively engaged in trying to prevent centralization of Internet trust, and decoupling it from the Five Eyes governments --- a worthy goal, I think --- should be adamantly against DNSSEC. But here's Snowden doing the opposite.
It's not because Snowden is disingenuous. I think he's a true-believer. It's because he doesn't understand DNSSEC.
> This is a weird response to a comment that quotes Snowden at length providing technical advice to the IETF.
Viewed another way, its a perfectly obvious and not at all weird response to a comment that quotes Snowden explicitly disclaiming that he is any particular, before providing a very vague general impression of things "like" a particular technology about which he was specifically questioned, without providing anything that looks like actual specific technical advice.
I think you're poisoning the well here. I haven't seen anyone suggest we should use Snowden as a technical advisor or anything of the sort.