[CFRG] Re: Silithium - A Compact, Efficient and Non-separable Hybrid Signature

Neil Madden <neil.e.madden@runbox.eu> Thu, 16 July 2026 10:06 UTC

Return-Path: <neil.e.madden@runbox.eu>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D7609117B9893 for <cfrg@mail2.ietf.org>; Thu, 16 Jul 2026 03:06:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784196413; bh=iA/IxPrjxXDEL/diwqDKCE9BsP/DnPiM3yKqTpbJcKU=; h=From:Subject:Date:References:Cc:In-Reply-To:To; b=npK8sWsdx10hmoWEiEJy/Tw1tt0U3F+L5gSDKfKatJSOc9OmzI48jNumiJo2FgWPu J5q+5DovUj+rLcb+H205Qiq2vimnQTxKW4ok0Ss+w9hqW8xbI2/3KU1lDJExot9LC3 TrivJmbQXgolA5NgSaNc8j8ueoj9JHvcNerkVroU=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.798
X-Spam-Level:
X-Spam-Status: No, score=-2.798 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=runbox.eu
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7kKNZjWyKWIp for <cfrg@mail2.ietf.org>; Thu, 16 Jul 2026 03:06:51 -0700 (PDT)
Received: from mailtransmit04.runbox.com (mailtransmit04.runbox.com [IPv6:2a0c:5a00:149::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 468FF117B987C for <cfrg@irtf.org>; Thu, 16 Jul 2026 03:06:51 -0700 (PDT)
Received: from mailtransmit02.runbox ([10.9.9.162] helo=aibo.runbox.com) by mailtransmit04.runbox.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.93) (envelope-from <neil.e.madden@runbox.eu>) id 1wkIzK-003goF-VB for cfrg@irtf.org; Thu, 16 Jul 2026 12:06:42 +0200
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=runbox.eu; s=selector2; h=To:In-Reply-To:Cc:References:Message-Id:Date:Subject: Mime-Version:From:Content-Transfer-Encoding:Content-Type; bh=4K/WLYocsWv4nHGVRa4+f1ahZXFHQE+1UZ6eAXzANR8=; b=LEdK9mdGFV93cXsCVVx0rd9ul5 RJiHigaOG1H3M04Hh3X7qn7DrzEk1vokodtrMykmqgKxQ86RDEaU0pGBuukOMOFskx7X7VmhH2JLk gRf4ceYz+K830kLUUnhA2Q0YRmGUWODbf7nbFHLSgsjXWkMSvZpBWMyEMasGcGakB/8VTAfQ77BQZ mP85+t/GljUb5Z7sd6J1ZhEaINyrMfkMKezP116niwaD2BB118IYWU0mzln9GlmIQC1AD1RjJkq2A c7F6bV//a+6cRDADGcEXXHIORAEkGwM8uYYtaRWn0YVEiZXrTf/g95jBbpBau9pjAcvUxHKupoEIt HzHIU86A==;
Received: from [10.9.9.74] (helo=submission03.runbox) by mailtransmit02.runbox with esmtp (Exim 4.86_2) (envelope-from <neil.e.madden@runbox.eu>) id 1wkIzK-0000BW-IT; Thu, 16 Jul 2026 12:06:42 +0200
Received: by submission03.runbox with esmtpsa [Authenticated ID (1456009)] (TLS1.2:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.95) id 1wkIzD-003ZeH-K2; Thu, 16 Jul 2026 12:06:35 +0200
Content-Type: multipart/alternative; boundary="Apple-Mail-CA196329-B3FB-417A-9291-26F3E285E7FF"
Content-Transfer-Encoding: 7bit
From: Neil Madden <neil.e.madden@runbox.eu>
Mime-Version: 1.0 (1.0)
Date: Thu, 16 Jul 2026 11:06:34 +0100
Message-Id: <BB9FA298-5346-4C22-B2B4-59B0CC8B32AA@runbox.eu>
References: <AS4PR07MB88251F744A2AF76E4CCD777889C72@AS4PR07MB8825.eurprd07.prod.outlook.com>
In-Reply-To: <AS4PR07MB88251F744A2AF76E4CCD777889C72@AS4PR07MB8825.eurprd07.prod.outlook.com>
To: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>
X-Mailer: iPhone Mail (23F81)
Message-ID-Hash: ZBOXUDJD3ZZVU6QFRH6Z526GTCCTJBPD
X-Message-ID-Hash: ZBOXUDJD3ZZVU6QFRH6Z526GTCCTJBPD
X-MailFrom: neil.e.madden@runbox.eu
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0; header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: cfrg@irtf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [CFRG] Re: Silithium - A Compact, Efficient and Non-separable Hybrid Signature
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/Ccn3fa4VEvuHiTCY_mH14bMA9-E>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>


> On 16 Jul 2026, at 09:17, John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org> wrote:
> 
> 
> There seem to be different opinions about the purpose of hybrids. The more obsolete cryptographic components PQ/T hybrids rely on, the more important it is to enable a migration path for removing those components once they become pure overhead and no longer provide meaningful security. In my view that will happen sometime around 2035.

Is this guesswork or based on something concrete? As I understand it there is still a non-negligible chance that cryptographically-relevant quantum computers (CRQCs) never happen and we end up reverting back to pure EC at some point in the future. Do I think that is the most likely scenario? No. But I don’t think it’s a foregone conclusion yet. Certainly, progress in terms of actual “qubits on the ground” doesn’t currently seem too alarming [1]. But I also accept I could be wrong about that. 

If that scenario were to happen, I think we’re in danger of losing an awful lot of credibility. 
A competent risk assessment would surely consider all plausible possible outcomes and have contingencies for all, but in the cryptographic community we seem to have already decided, ahead of the engineering, that CRQCs are inevitable and that pure-PQ is the only conceivable future. I hope we are collectively correct in that bet, otherwise I suspect we may not be taken seriously again. 

Hybrid designs that allow smooth migration from EC to hybrid and then to *either* pure PQ or back to pure EC seem sensible to me. 

[1]: https://neilmadden.blog/2026/07/02/are-we-any-closer-to-the-quantum-apocalypse/

— Neil