Re: [CFRG] Google's (current) Threat model for Post-Quantum Cryptography

Stephen Farrell <stephen.farrell@cs.tcd.ie> Tue, 12 March 2024 22:24 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A830C14F6B5 for <cfrg@ietfa.amsl.com>; Tue, 12 Mar 2024 15:24:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.007
X-Spam-Level:
X-Spam-Status: No, score=-7.007 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Os9vcUEffH4z for <cfrg@ietfa.amsl.com>; Tue, 12 Mar 2024 15:24:09 -0700 (PDT)
Received: from EUR01-HE1-obe.outbound.protection.outlook.com (mail-he1eur01on071c.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe1e::71c]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ABBA2C14F6B1 for <cfrg@irtf.org>; Tue, 12 Mar 2024 15:24:09 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cZY0R07xUpbaW/SrFN8f1HUQJYXJ1e6MAL3ivD48FYZviMYoPfm92hGcUIejc5e5p1nz0CEJmw27Jis98TaQ00VXSHKeb3GScvcE3sI8u3L0LmG0686ymeQk/Yzhe18Q0i230sm8r4A0p4S6G1SQGKVVhkNNRW9G+KhajKe6fmO71BQ1QqKW3sYuXlrTtMKR7bbAwXGS9vW5frEvn9hiEg9eVCVhGI8J1AuYd9YGfq0lnN1ucWCM5UWUB+HQUmKQW2XTpit27Rq4ulHKWIxSzzutPX9+ihWmc/fDwDBvcEUITAWd5VB5EFgv7oYRxOuP3qANgWMd7pf3HQxYVokjXw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=8PklL17F2MNeeNbmWGzyXdGJDdtEG0C6x+I2ebC+qLM=; b=M4Wc4GAOugjalcgdmbFYqj6ughogzQTANBBAsXA0tdO75jg50rswryBoyqfhgLHpCyD4qn4H50YkucIVUu4QjHjTo2sP2SRAkOX7WZP1TvDHF9u2eHqjNV1nhgJkFghI3RFkvEjl51mrxyzGawSIWVPJRi+cncCminVpY8VcPnMFnkQ+pz8fSi6X5ug7Bp7Iub6tgm9DxZLGS6xM6PuPbGwK/r8tsR1H/srZwrp1w85fyAFKrizP2SRHIBcv2QWbeK9iHLhhSKW14S3VVFkTk3NcSpZZLdSECeaUKj/W5A+cgn9P4n8TQ1fR/rABDbSJfW5+yflL0UiQwnlApeiqgA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8PklL17F2MNeeNbmWGzyXdGJDdtEG0C6x+I2ebC+qLM=; b=mbGAT8uR/r3j4iXfgQhAMnfxgNCcvhcwGVeGk89tGoUOhUgskjS7Le4dkeouPg6r9TqUj3ljUlZ9IP1xqEZ0zB4FoDyyF545wb6al8JuASANM4YaWqHdiy5Bn6PCIfARZInSlMOHGEwNkor1LyWpErWIK83pIZBmlxidOn+9QzIJaYWUOl9vSU/L4oT1oFoZ9Pz4sjDg2RqCisyVHLcLSoA8vkPqzOKbNRh5oorzSz+jOUo8UNxa302uLun/2Tp+VnaHP8+5G1ElsEWis2qwTngNS950tpQAj0kP/UUDOFjhyZ2Cmh43KnJzLZd9U6kMBtUiHzsSFnIlm7fIUM4qvw==
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15) by GV1PR02MB8443.eurprd02.prod.outlook.com (2603:10a6:150:8c::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7362.33; Tue, 12 Mar 2024 22:24:04 +0000
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::29da:8147:6e33:c2b7]) by DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::29da:8147:6e33:c2b7%4]) with mapi id 15.20.7362.035; Tue, 12 Mar 2024 22:24:04 +0000
Message-ID: <3ee20938-95a5-40d3-9930-8ae8db3ed3d8@cs.tcd.ie>
Date: Tue, 12 Mar 2024 22:24:02 +0000
User-Agent: Mozilla Thunderbird
Content-Language: en-US
To: Orie Steele <orie@transmute.industries>, "Salz, Rich" <rsalz=40akamai.com@dmarc.ietf.org>
Cc: "cfrg@irtf.org" <cfrg@irtf.org>
References: <2D2B67B4-9E1D-46DA-A2EE-08D89BFE254D@akamai.com> <CAN8C-_J0_bQRTymi0O+OtNOcid6P5m9EYj-MaZP_MJe=_VXKiw@mail.gmail.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Autocrypt: addr=stephen.farrell@cs.tcd.ie; keydata= xjMEY9GzphYJKwYBBAHaRw8BAQdAo6JvjmSbxHdQWPZdvciQYsHhM1NxQBU398Mmimoy4p7N M1N0ZXBoZW4gRmFycmVsbCAoMjU1MTkpIDxzdGVwaGVuLmZhcnJlbGxAY3MudGNkLmllPsKQ BBMWCAA4FiEEMG54R8tZDyZFrDOn5Njp+ZeoM90FAmPRs6YCGwMFCwkIBwIGFQoJCAsCBBYC AwECHgECF4AACgkQ5Njp+ZeoM93bogEA25ElRyX0wwg+kGEN1AoL60MoZfvQZ/VtmXY6IC5j +csBAIBpkL5ySuzJK2zLNZn9qQGht8IaUcA7cvDcLvS2uHUEzjgEY9GzphIKKwYBBAGXVQEF AQEHQILCPWOwW36e8D3pY8GmvvtItIT+A5uV80ist+WokVsQAwEIB8J4BBgWCAAgFiEEMG54 R8tZDyZFrDOn5Njp+ZeoM90FAmPRs6YCGwwACgkQ5Njp+ZeoM92bcAEA8R+8cpqRUIS+SoAN iO05xE6O/wEx8/e88BqzAYki3SoBAOQdwiPX+MQrAxkWD8xxOsdMOAtxYKpkD1n8aPJUw6QJ
In-Reply-To: <CAN8C-_J0_bQRTymi0O+OtNOcid6P5m9EYj-MaZP_MJe=_VXKiw@mail.gmail.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------WWLbHQ6ROYmEbXo81Rkge08h"
X-ClientProxiedBy: DB7PR05CA0012.eurprd05.prod.outlook.com (2603:10a6:10:36::25) To DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: DB7PR02MB5113:EE_|GV1PR02MB8443:EE_
X-MS-Office365-Filtering-Correlation-Id: 439e05eb-fd77-4556-00f8-08dc42e31fb3
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: uxcE4M1XhhCxr/5uqje3EYIKlbUZ9t/II9FFFuCXjHC+PrrwMQCT3gWrN/pIE+zjqJp92zX0lBrgYISZBGIy2XF5YgxcSLGsSkQDzrb+FT0VlDG+mQvvaT6c2iJYT2lIaHqnsKHaUe2XLHDqKJtax6poHnG3VLl1cTIG5gNRVrNtgbZVjNhgoc6oBihFdZwcx4ygYkDjD+T4OxQoFvConmD2hqh5GoVGbESeIPBEG0TKDGNAaf/egOVvfJHSg1XJOYSTt+jcHuNNtF1OLxNH5qDVUmXGCDL7keqojgE6ug/tXLrL5BQljxfmPhcqmwclgpNVz7qcyxmw+S0Y+fSX9lP7Jd7EfgCz7yNSKmafiKu9HjIZEvEfdQriTxyC5ha27w5tSfoSMKQU1ByggLB8WKf9+pDBGWC5hDiLDxWNtL044HYz3lA5nZ/Rg6NhW9Z/AOwJ+ZohzMlcAULD6QK3h6atmQYIJEQhmMEKCMgvU+GmGHGPrI1pG58C2qRH44HtnmTgwKBslgvk0uIesmNvHK8N/UF6afWQAUpKaxkYnsfCIifTj2G9wrsPbLT2bCSuFjibBTRPl8E7jUhOZcFVLKiAKlfRYL5fIVMpglXDBcIBhQrv6+s4XWlZs0icvp9LlrAhSLe0E7WrLKOu3v/kjn81wOBj0BNlVAigcjWHDfw=
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB7PR02MB5113.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376005)(1800799015); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: OLVzFy1/4njZR9PPFeKz28H/poARKt+5o8f+cp5wkeqZb5wEVSQbTSuq8ZJAdBGIFSToMPXfte0IScngHhB7WhwDZ+Pp6zg30AkfbryP7GH5YY4JDv731f0rHT27KbQIrvdLzdRwrPWAiivqm1FQ2RExAqemh3FokZluEXTw8Kypr4KbHvaHxJu63osbWK3CSK9Bt66cMhkSqQKW6WyleONLeAG8WJNLi/19irVGrNcPpvAdaSneeGZzSVKQ6EEJEDYb6oZOouhIDlO/n2LmTs1uXfUvW3uw6sn87yxe/TgW7BEhT0lGxDmToRjwgLToC9Y1LVz8bb9ACA1gDhtoXoo2eEcLCWeA9WtP7SPbesqNUm4H3xw5mvfLdsY8w7naf8yaGTGxWtKJ4noZvWFYOT2JLn8ptaK9Fu53nYGAKEOwCD5BaVxc6KzjrBelXlpqtyEwAmsHLgG/fo3nA/t6AZI16d2jNTAzABhoxcPBaZXMR1UocMVx3y4Vvth720iUikwasPdfYh51I8wNeygJDVucXIOvxO4100HbwYc+nrFjsw83PixuzYn+xlWGFwJPVZmHE4q8G7sLq6sAOdsFIze8q3kMaoOvakj5fnwuR1yezxlvOUedvhEeydPC1zwlXBSQ8XVcpmCB7yB6u98satMEhEW0yorSCutV3tswR8RrXvKoXK9BnXVIU4+O8uc78IRp9xOgLdzvcYgI5xAgOThign9ytk4M5C9t3oLpBsRHREohRJbbfPbsKqEoJvuX34BJlr8q9hKZxIrVuUWnkJBlAkOoHPyZPhgw3qGPK98xUYue5A9n18rzVlfg3UnHjBSQB3DU3XYzupArS7Ht/UHrDtgECOPOSKVhv8r7i8m4FGzGIZumg/tmksO23zM2RKCe+FsNTDElBP2+rihSjBaVlrTJDZSSv80zVCpjd82KLiOHmXPcsc/38njBBg4e901kLXNMrX5y/MtZnf+B0jFEI33ex7Wjk6D+tlFl+Am5fZ4ZKIPpB0JvjX9dO1BGoPGwcfjfx7CW4tqYvxoxBZniCAaxk6Fc/Ct4gnCs3IXZCCWQ4ze1SoC0EvCKnK6d5J0SH0/vVDFiqNuqkpGPoIg2rLF9xCvpsRD5WAyhwHjUQVtOcnrU5B1NWEJ//yaaSu2c5Jh37NijHi+63J+iguBiJz4IEzZK/tTm6mFfbEkShIByiyNhclZAVX8tCL89HONwZRsRk+WYm3IcUdPTI99j8EIP423T1lesoI2MelV0OwzdYuJkhM0XPYoZSmnOYt206+tzRNJ4z44952YTR3m9begBevUHPBIydBZ1+rPWM+ZhcR6AtXedvDAvYNhRbQRl6JRzLfXtrecfZMg0DYs9QPfNOmd3GoCOYsOpBhUqZpHBBVLj8xCuiOigDCfNI6Daj8a3W6/vdsU24zqbiWjtNG1ujMHegp1WO1W3Qla+xWxxYQ3AbNdlGxKKNZcvt8AgN7MSNAzVkWz06XJqAzglgjqIebZHnNpodxrdWOGVJFyk48gjCWVG/zYyYaAine58cks4v29yzL+WvVGmcCIkm6j4IwBQUET1gEIXtsWElwQDCfw5Bdnj6+pKNNfSv0gq+0pvAeEwN7XeVwgAXbDF+sNz7w3M2y9MFPQJnA/2O0KFIjMFCrQtQgveLlW4
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: 439e05eb-fd77-4556-00f8-08dc42e31fb3
X-MS-Exchange-CrossTenant-AuthSource: DB7PR02MB5113.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 12 Mar 2024 22:24:04.3227 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: OlfRZV9gwHaO8fM4G7ACnSBKZM7/pYYAxQvHmWOd+6ubz+WeAOGYxzQNyre2q7KC
X-MS-Exchange-Transport-CrossTenantHeadersStamped: GV1PR02MB8443
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/8FFSU82FYPnirLT2XSyd9kaGPTY>
Subject: Re: [CFRG] Google's (current) Threat model for Post-Quantum Cryptography
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://mailman.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://mailman.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Mar 2024 22:24:14 -0000


On 12/03/2024 22:04, Orie Steele wrote:
>> Our current recommendation is to use either Dilithium3 (FIPS 204, ML-DSA)
> in hybrid with ECDSA/EdDSA/RSA, or SPHINCS+ (FIPS 205, SLH-DSA) for this
> use case.
> 
> I fear how many different variants of these we may see in protocols without
> some baseline guidance from CFRG.

I prefer the bits saying to mostly not worry about signatures
for now and chill out a bit wrt those. (yeah, my interpretation:-)

If we did pay attention to that (and we should) I think it takes
away most of the problem with hyrbid combnbatorics.

I'd love it if cfrg had consensus on something like that as I
think it'd save a bunch of IETF WGs a bunch of time over the
next couple of years.

Cheers,
S.