Return-Path: <rlb@ipv.sx>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1])
	by mail2.ietf.org (Postfix) with ESMTP id 56D6A7E66C49
	for <cfrg@mail2.ietf.org>; Wed, 29 Oct 2025 14:04:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level: 
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001,
	SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key)
	header.d=ipv-sx.20230601.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31])
	by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id 9M_E-MWql91T for <cfrg@mail2.ietf.org>;
	Wed, 29 Oct 2025 14:04:05 -0700 (PDT)
Received: from mail-il1-x134.google.com (mail-il1-x134.google.com
 [IPv6:2607:f8b0:4864:20::134])
	(using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by mail2.ietf.org (Postfix) with ESMTPS id D47417E6687B
	for <cfrg@irtf.org>; Wed, 29 Oct 2025 14:03:30 -0700 (PDT)
Received: by mail-il1-x134.google.com with SMTP id
 e9e14a558f8ab-430d098121cso1171695ab.0
        for <cfrg@irtf.org>; Wed, 29 Oct 2025 14:03:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=ipv-sx.20230601.gappssmtp.com; s=20230601; t=1761771810;
 x=1762376610; darn=irtf.org;
        h=cc:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:from:to:cc:subject:date:message-id:reply-to;
        bh=dQ49dfctiW5xG8+nki0mMbTYi+O+JgmzaxE9nk+No0s=;
        b=ytgjNiBNx9Y95XxCjcSVDz6B6huuW7zjqBxTCrM1n24l3oBFM6StIc+96tAVB3hbsy
         G4bwmUlLD3CJNPwPTdEknQZkTs88+1aRLX81cedW5J/Xj9TeLqUioINHJMUVI5odXnem
         KHHIUxxSpazMve368yPe110J5Glq4pwhczT6Um304lGHrFWe4AUs27nExUTVech0oFvt
         oGXWRe77cdxhfg8pDvzKqTp8pPtiK/1GsSp21O8+vMlmr94Evra+tWHiRPTK02NMdt9v
         U7ZQG5QO/MDsMVuZPghyJFp9TsHsw+9L1O63SiSzIQu3ojMBeuSeD6IJkVDY4plT1PK3
         igKw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20230601; t=1761771810; x=1762376610;
        h=cc:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id
         :reply-to;
        bh=dQ49dfctiW5xG8+nki0mMbTYi+O+JgmzaxE9nk+No0s=;
        b=w/0GvPNRgXvmYLalu2zNNEDa1bEV/dtQjEaK4wyMYbCWwwFolB5H1tJpFIVVX0FOQe
         aNDynPSzStXjEi2QzI2XhWMaTgCSzuPOdNe2vGvnjfbxS0nwfLcmK4+jIc+Hy7PounnN
         PAd4H5qx6xgLr8Z1lwtJpQVgohi6UyTRjE0hlgjbaWYdlRwetK2cf3NtyUr/7wraE5dj
         bALz39MCDI4FDRN0lFxBzAo5nOG+p+6ZRtiFoa5/I885FjuYgWT1XqA1TDxFVzhRwspK
         h67buCxr3ZZHmArutE84jAfNPdiWcNhtDvUGzOUul5g9CmjuGlMoLvfJKfYIWkh0ESK3
         CXtg==
X-Gm-Message-State: AOJu0YzAGgZAJ0exVxY6Ob7l9bV7VzFprzGiLOEjdWwiUgWzmMZrMO8s
	baigElh/RVjIbHg3qn+IOzfWgEkGyaozrbihUdVyDIxzm62J8ifGQmlAQtgCtKsUIpEGsiIHOxr
	qlzy9kwAcMAzpXatxqk5FznJ4ar8NN1byQmSr0+Uh1g==
X-Gm-Gg: ASbGnctAkn4DKSOr0LN0vAMBBrvVWcmn3x+pKwP2gBVSRnP3JeYXfCPiby4agtLzyIc
	sHR20lhRbbuaV27UyPDNWc9sgpYFTNRu8p0GmKqvtY9NOcW/kq+c2895L83ogYpFbfCJKMi51G1
	hlGjodrA2TVm9lNhdQkRAVp5h+VGnQjPH/kUey+HH/zlCJqpDal8AvfXWvjxOUDLqeEQyXzuHfT
	J+CrxkezGbtSXCA9g1Ura6WvQu7FmQKum1dxcaQGccE7CDwTfbtjoxNew==
X-Google-Smtp-Source: 
 AGHT+IH4th9RwacZJX57rmL1gHRNmTDdee5hD1xT0zTH1ZJTvAvqsDwHZOmaHTpQWo632/kIeWLShh6DObjXUfAztCo=
X-Received: by 2002:a05:6e02:3486:b0:430:aec5:9bee with SMTP id
 e9e14a558f8ab-432f8f871a8mr51741965ab.7.1761771808965; Wed, 29 Oct 2025
 14:03:28 -0700 (PDT)
MIME-Version: 1.0
References: 
 <CAKZgXHpQH7PcGiz9FxFCmr1hE29EGx9WuPDP-RFfem-2Bjyh6w@mail.gmail.com>
 <CABcZeBNR7TT6+fMPjdK7N-v6hWgLLHxhDw-D4qGhuOVfsUgqyw@mail.gmail.com>
 <CAKZgXHpW9PpuhUs=sS9Q8d1MMqEyWh8hp3khp2Vuryf3LANcLw@mail.gmail.com>
 <2D85ACB8-26D1-4E42-B4BE-DD5CD9BDE33A@nps.edu>
 <CAEEbLAZOjWigARX4nn+88qJ1cJomaGz6UTUepuaY3wddjpWSuw@mail.gmail.com>
 <CABcZeBN75WDp=g6Zd-vFm_B7mtrU0F97iA54RT98up=tFf_mKQ@mail.gmail.com>
 <CABcZeBOmNiJgT7QZS48t=oCk40cbwXcW8VA8wRf5h8kuo+gPuw@mail.gmail.com>
 <2eff0118-f6c9-4292-b28d-c12e7aefc358@dennis-jackson.uk>
In-Reply-To: <2eff0118-f6c9-4292-b28d-c12e7aefc358@dennis-jackson.uk>
From: Richard Barnes <rlb@ipv.sx>
Date: Wed, 29 Oct 2025 11:03:17 -1000
X-Gm-Features: AWmQ_bkMHcrYhT1pbYYU_LBClKuCp3LVarzwZz-WfONtRJLS2Jg4RlcmPmExmKM
Message-ID: 
 <CAL02cgSVuoFUos4QnFZZDKh-kTh4jJhH6DE39E2TD5-vcWPwXA@mail.gmail.com>
To: Dennis Jackson <ietf=40dennis-jackson.uk@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="000000000000d9646f0642527617"
Message-ID-Hash: QXG6QENMUHPLQAEDQ6CR6QWMTCJGXUVA
X-Message-ID-Hash: QXG6QENMUHPLQAEDQ6CR6QWMTCJGXUVA
X-MailFrom: rlb@ipv.sx
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0;
 header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia;
 implicit-dest; max-recipients; max-size; news-moderation; no-subject;
 digests; suspicious-header
CC: cfrg@irtf.org, LAMPS <spasm@ietf.org>, hpke@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5BCFRG=5D_Re=3A_=5Bhpke=5D_Re=3A_Re=3A_Re=3A_Re=3A_New_labels_in_?=
	=?utf-8?q?draft-irtf-cfrg-concrete-hybrid-kems-01?=
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/cfrg/UbGD0aphN1UIS_relATdUhuRi38>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>

--000000000000d9646f0642527617
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

FWIW, here's a PR that does just that:

https://github.com/cfrg/draft-irtf-cfrg-concrete-hybrid-kems/pull/37


On Wed, Oct 29, 2025 at 11:02=E2=80=AFAM Dennis Jackson <ietf=3D
40dennis-jackson.uk@dmarc.ietf.org> wrote:

> My understanding is that the new labels in the CFRG draft were chosen
> because nobody could agree on what human readable content to include.
>
> The timing around when the drafts landed & the communication around the
> label change has made things messy and I totally get the frustration ther=
e.
>
> A pragmatic way forward would be to just use the hex and drop the ASCII
> from the cfrg draft:
>
> 0x7C2D28292D7C for X-Wing
> 0x5C2E2F2F5E5C for P256-ML-KEM1024
> 0x207C202F2D5C for P384-ML-KEM1024
>
> These numbers are as good as any other and it paves over the issues folks
> already ran into with the (unchangeable) X-Wing label.
>
> Best,
> Dennis
> On 29/10/2025 20:43, Eric Rescorla wrote:
>
> Following up to myself.... I'm also fine with the LAMPS strings.
>
> -Ekr
>
>
> On Wed, Oct 29, 2025 at 1:27=E2=80=AFPM Eric Rescorla <ekr@rtfm.com> wrot=
e:
>
>> I would make a few points here:
>>
>> I don't have a strong opinion on whether we ought to have structured
>> strings or just 6-byte constants but ISTM that having the spec contain
>> strings which contain special characters are a clear safety hazard, and =
the
>> only motivation for them seems to be to make a Star Wars joke, which rea=
lly
>> doesn't seem like a priority for the RG. That seems more like a bug than=
 a
>> feature to me. With that said, while the X-wing label is unfortunate, I
>> don't think anyone is proposing to change it, but no such considerations
>> exist for the other value. To that end, I propose the following:
>>
>> - Render the labels only as hex values.
>> - Replace the non-X-wing labels with values which don't happen to
>> correspond to escape characters. The obvious thing to do here is just to
>> use a simple counter, so we can use (x00...00 and 0x00..02) but I could
>> imagine other approaches.
>>
>> The net effect of these is to slightly reduce the surface area for error=
s
>> without creating an interop problem or arguments about the semantics of =
the
>> strings.
>>
>> Finally, I would observe that arguments of the form "we need to get
>> things out now so we need to do things the way I prefer" are less
>> persuasive than "we need to get this now so I'm prepared to do things a =
way
>> I don't really like".
>>
>> -Ekr
>>
>>
>>
>> On Wed, Oct 29, 2025 at 1:11=E2=80=AFPM Sophie Schmieg <sschmieg@google.=
com>
>> wrote:
>>
>>> The labels are simple numeric codepoints:
>>> 0x7C2D28292D7C for X-Wing
>>> 0x5C2E2F2F5E5C for P256-ML-KEM1024
>>> 0x207C202F2D5C for P384-ML-KEM1024
>>> in little endian.
>>> And yes, I concur with Filippo, we need to be able to ship without bein=
g
>>> held up by discussions on naming things, and simple numerical values li=
ke
>>> the ones above allow us to do just that.
>>>
>>> On Wed, Oct 29, 2025 at 12:17=E2=80=AFPM Hale, Britta (CIV) <britta.hal=
e=3D
>>> 40nps.edu@dmarc.ietf.org> wrote:
>>>
>>>> I concur with keeping clear and human-readable ciphersuites (e.g.,
>>>> =E2=80=9CQSF-P256-MLKEM768-SHAKE256-SHA3256=E2=80=9D). Post quantum mi=
gration is
>>>> challenging enough without adding a further mapping that humans can
>>>> mis-interpret, which can itself lead to introduction of vulnerabilitie=
s
>>>> while attempting use of post quantum algorithms.
>>>>
>>>>
>>>>
>>>> If there are any cases where shorthand is absolutely needed (e.g., in
>>>> specific WGs where counting bytes matters), then reference strings oug=
ht to
>>>> be simple such as a numeric mapping to specific suites. ASCII art make=
s it
>>>> difficult to ensure correctness, even among knowledgeable individuals,=
 as
>>>> is evident by the examples already encountered. We should not be makin=
g
>>>> standards intentionally more difficult to follow for less experienced
>>>> individuals.
>>>>
>>>>
>>>>
>>>> Britta
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> *From: *Mike Ounsworth <ounsworth+ietf@gmail.com>
>>>> *Date: *Wednesday, October 29, 2025 at 11:11=E2=80=AFAM
>>>> *To: *Eric Rescorla <ekr@rtfm.com>
>>>> *Cc: *LAMPS WG <spasm@ietf.org>, CFRG <cfrg@irtf.org>, "hpke@ietf.org"
>>>> <hpke@ietf.org>
>>>> *Subject: *[CFRG] Re: New labels in
>>>> draft-irtf-cfrg-concrete-hybrid-kems-01
>>>>
>>>>
>>>>
>>>> NPS WARNING: *external sender* verify before acting.
>>>>
>>>>
>>>>
>>>> As as pointed out by Daniel Van Geest in another thread, the label
>>>> for MLKEM1024-P384 is supposed to be " | /-\", but in the published ve=
rsion
>>>> of the cfrg draft (both HTML and TXT), it displays as ` | /-` (note th=
e
>>>> missing backslash). So that means that the kramdown2rfc tooling is not
>>>> handling this properly.
>>>>
>>>>
>>>>
>>>> So when I said "This is GOING to lead to at least incompatibilities if
>>>> not CVEs" I didn't realize that we already had one in the draft.
>>>>
>>>>
>>>>
>>>> The point is this:
>>>>
>>>> The LAMPS doc is already in WGLC (months later than we wanted), using
>>>> the labels from YOUR -00 (minus the SHAKE256 component). I made that c=
hange
>>>> in consultation with you guys as part of the CRFC Interim in Sept. You=
r doc
>>>> is not in WGLC yet, so can you please change your labels to match?
>>>>
>>>>
>>>>
>>>> On Wed, 29 Oct 2025 at 12:47, Eric Rescorla <ekr@rtfm.com> wrote:
>>>>
>>>> I can't speak for what has or has not happened in terms of interop, bu=
t
>>>> on the
>>>>
>>>> substance of the labels I agree with Mike. I strongly prefer simple
>>>> human-readable
>>>>
>>>> labels to ASCII art Star Wars references, no matter how clever those
>>>> references
>>>>
>>>> might be.
>>>>
>>>>
>>>>
>>>> -Ekr
>>>>
>>>>
>>>>
>>>> On Wed, Oct 29, 2025 at 10:36=E2=80=AFAM Mike Ounsworth <
>>>> ounsworth+ietf@gmail.com> wrote:
>>>>
>>>> draft-irtf-cfrg-concrete-hybrid-kems-01 publish on Oct 20 and made the
>>>> following label changes:
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> "QSF-P256-MLKEM768-SHAKE256-SHA3256" -->  "|-()-|"
>>>>
>>>> "QSF-P384-MLKEM1024-SHAKE256-SHA3256" --> " | /-"
>>>>
>>>>
>>>>
>>>> Please tell me this is a joke. Then please remove this from the draft
>>>> and put the labels back to sane alphanumeric. I'm sorry for strong lan=
guage
>>>> below, but this makes me mad.
>>>>
>>>> I have been bending over backwards to make the LAMPS thing match the
>>>> HPKE thing, including multiple rounds of interop-testing against your =
test
>>>> vectors and changing the LAMPS draft, reference impl, and test vectors=
 to
>>>> match yours. This has resulted in delayed publication of the LAMPS dra=
ft by
>>>> several months to accommodate interop with the HPKE draft. The LAMPS
>>>> Composite-KEM doc went into WGLC on Oct 17 now using HPKE-style labels=
 of
>>>> the form "QSF-MLKEM768-P256-SHA3256" that we pulled FROM YOUR DRAFT in=
stead
>>>> of the OID-based labels we had before. Then on Oct 20 you publish a ne=
w
>>>> version that goes and changes the labels to this nonsense. Can you guy=
s
>>>> please at least pretend like you care about interop between these two =
docs?
>>>>
>>>> My specific objections to more ASCII art labels:
>>>>
>>>> 1. We're already having interop problems at the PQC hackathon group
>>>> because of the backslash in the xwing label -- for example, in python =
you
>>>> have to put the constant in your source code as "\\.//^\\" to prevent =
it
>>>> from interpreting that as an escaped dot and double-quote. We've also =
had
>>>> similar problems representing this label properly in HTML and markdown
>>>> docs. Now you want more labels that have both backslashes and now spac=
es.
>>>> This is GOING to lead to at least incompatibilities if not CVEs.
>>>>
>>>> 2. The label is not human-readable; it doesn't tell my anything useful
>>>> about the content, nor will it be easy to debug mistakes in source cod=
e or
>>>> config files. At this point, assigning a numeric codepoint would be
>>>> preferable.
>>>>
>>>> 3. This does not establish a naming convention that is easily
>>>> extensible to other hybrid combinations.
>>>>
>>>> I have been doing everything in my power to work behind the scenes to
>>>> get interop between these two documents, and it feels like you guys ar=
e
>>>> doing everything in your power to obstruct it.
>>>>
>>>>
>>>> Can you please put your labels back so that they match the LAMPS draft
>>>> using the pattern "QSF-MLKEM768-P256-SHA3256".
>>>>
>>>>
>>>>
>>>> (PS this is a re-send from the correct email address)
>>>>
>>>>
>>>> -Mike
>>>>
>>>> _______________________________________________
>>>> CFRG mailing list -- cfrg@irtf.org
>>>> To unsubscribe send an email to cfrg-leave@irtf.org
>>>>
>>>> _______________________________________________
>>>> hpke mailing list -- hpke@ietf.org
>>>> To unsubscribe send an email to hpke-leave@ietf.org
>>>>
>>>
>>>
>>> --
>>>
>>> Sophie Schmieg | Information Security Engineer | ISE Crypto |
>>> sschmieg@google.com
>>>
>>>
> _______________________________________________
> CFRG mailing list -- cfrg@irtf.org
> To unsubscribe send an email to cfrg-leave@irtf.org
>
> _______________________________________________
> hpke mailing list -- hpke@ietf.org
> To unsubscribe send an email to hpke-leave@ietf.org
>

--000000000000d9646f0642527617
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>FWIW, here&#39;s a PR that does just that:</div><div>=
<br></div><div><a href=3D"https://github.com/cfrg/draft-irtf-cfrg-concrete-=
hybrid-kems/pull/37">https://github.com/cfrg/draft-irtf-cfrg-concrete-hybri=
d-kems/pull/37</a></div><div><br></div></div><br><div class=3D"gmail_quote =
gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, Oct 29=
, 2025 at 11:02=E2=80=AFAM Dennis Jackson &lt;ietf=3D<a href=3D"mailto:40de=
nnis-jackson.uk@dmarc.ietf.org">40dennis-jackson.uk@dmarc.ietf.org</a>&gt; =
wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0=
px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><u></u>

 =20
   =20
 =20
  <div>
    <p>My understanding is that the new labels in the CFRG draft were
      chosen because nobody could agree on what human readable content
      to include.=C2=A0</p>
    <p>The timing around when the drafts landed &amp; the communication
      around the label change has made things messy and I totally get
      the frustration there.</p>
    <p>A pragmatic way forward would be to just use the hex and drop the
      ASCII from the cfrg draft:</p>
    <p>
      </p><blockquote type=3D"cite">
        <div>0x7C2D28292D7C for X-Wing</div>
        <div>0x5C2E2F2F5E5C for P256-ML-KEM1024</div>
        <div>0x207C202F2D5C for P384-ML-KEM1024</div>
      </blockquote>
    <p></p>
    <p>These numbers are as good as any other and it paves over the
      issues folks already ran into with the (unchangeable) X-Wing
      label.</p>
    <p>Best,<br>
      Dennis</p>
    <div>On 29/10/2025 20:43, Eric Rescorla
      wrote:<br>
    </div>
    <blockquote type=3D"cite">
     =20
      <div dir=3D"ltr">
        <div>Following up to myself.... I&#39;m also fine with the LAMPS
          strings.</div>
        <div><br>
        </div>
        <div>-Ekr</div>
        <div><br>
        </div>
      </div>
      <br>
      <div class=3D"gmail_quote">
        <div dir=3D"ltr" class=3D"gmail_attr">On Wed, Oct 29, 2025 at
          1:27=E2=80=AFPM Eric Rescorla &lt;<a href=3D"mailto:ekr@rtfm.com"=
 target=3D"_blank">ekr@rtfm.com</a>&gt;
          wrote:<br>
        </div>
        <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex=
;border-left:1px solid rgb(204,204,204);padding-left:1ex">
          <div dir=3D"ltr">
            <div>I would make a few points here:</div>
            <div><br>
            </div>
            <div>I don&#39;t have a strong opinion on whether we ought to
              have structured strings=C2=A0or just 6-byte constants but IST=
M
              that having the spec contain strings which contain special
              characters are a clear safety hazard, and the only
              motivation for them seems to be to make a Star Wars joke,
              which really doesn&#39;t seem like a priority for the RG. Tha=
t
              seems more like a bug than a feature=C2=A0to me. With that
              said, while the X-wing label is unfortunate, I don&#39;t thin=
k
              anyone is proposing to change it, but no such
              considerations exist for the other value. To that end, I
              propose the following:</div>
            <div><br>
            </div>
            <div>- Render the labels only as hex values.</div>
            <div>- Replace the non-X-wing labels with values which don&#39;=
t
              happen to correspond to escape characters. The obvious
              thing to do here is just to use a simple counter, so we
              can use (x00...00 and 0x00..02) but I could imagine other
              approaches.</div>
            <div><br>
            </div>
            <div>The net effect of these is to slightly reduce the
              surface area for errors without creating an interop
              problem or arguments about the semantics of the strings.=C2=
=A0</div>
            <div><br>
            </div>
            <div>Finally, I would observe that arguments of the form &quot;=
we
              need to get things out now so we need to do things the way
              I prefer&quot; are less persuasive than &quot;we need to get =
this
              now so I&#39;m prepared to do things a way I don&#39;t really
              like&quot;.</div>
            <div><br>
            </div>
            <div>-Ekr</div>
            <div><br>
            </div>
            <div><br>
            </div>
          </div>
          <br>
          <div class=3D"gmail_quote">
            <div dir=3D"ltr" class=3D"gmail_attr">On Wed, Oct 29, 2025 at
              1:11=E2=80=AFPM Sophie Schmieg &lt;<a href=3D"mailto:sschmieg=
@google.com" target=3D"_blank">sschmieg@google.com</a>&gt;
              wrote:<br>
            </div>
            <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0=
.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
              <div dir=3D"ltr">The labels are simple numeric codepoints:
                <div>0x7C2D28292D7C for X-Wing</div>
                <div>0x5C2E2F2F5E5C for P256-ML-KEM1024</div>
                <div>0x207C202F2D5C for P384-ML-KEM1024</div>
                <div>in little endian.</div>
                <div>And yes, I concur with Filippo, we need to be able
                  to ship without being held up by discussions on naming
                  things, and simple numerical values like the ones
                  above allow us to do just that.</div>
              </div>
              <br>
              <div class=3D"gmail_quote">
                <div dir=3D"ltr" class=3D"gmail_attr">On Wed, Oct 29, 2025
                  at 12:17=E2=80=AFPM Hale, Britta (CIV) &lt;britta.hale=3D=
<a href=3D"mailto:40nps.edu@dmarc.ietf.org" target=3D"_blank">40nps.edu@dma=
rc.ietf.org</a>&gt;
                  wrote:<br>
                </div>
                <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0=
px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
                  <div>
                    <div lang=3D"EN-US">
                      <div>
                        <div>
                          <p class=3D"MsoNormal"><span style=3D"font-size:1=
1pt">I concur with
                              keeping clear and human-readable
                              ciphersuites (e.g.,
                              =E2=80=9CQSF-P256-MLKEM768-SHAKE256-SHA3256=
=E2=80=9D).
                              Post quantum migration is challenging
                              enough without adding a further mapping
                              that humans can mis-interpret, which can
                              itself lead to introduction of
                              vulnerabilities while attempting use of
                              post quantum algorithms.
                            </span></p>
                          <p class=3D"MsoNormal"><span style=3D"font-size:1=
1pt">=C2=A0</span></p>
                          <p class=3D"MsoNormal"><span style=3D"font-size:1=
1pt">If there are any
                              cases where shorthand is absolutely needed
                              (e.g., in specific WGs where counting
                              bytes matters), then reference strings
                              ought to be simple such as a numeric
                              mapping to specific suites. ASCII art
                              makes it difficult to ensure correctness,
                              even among knowledgeable individuals, as
                              is evident by the examples already
                              encountered. We should not be making
                              standards intentionally more difficult to
                              follow for less experienced individuals.
                            </span></p>
                          <p class=3D"MsoNormal"><span style=3D"font-size:1=
1pt">=C2=A0</span></p>
                          <p class=3D"MsoNormal"><span style=3D"font-size:1=
1pt">Britta</span></p>
                        </div>
                        <p class=3D"MsoNormal"><span style=3D"font-size:11p=
t">=C2=A0</span></p>
                        <p class=3D"MsoNormal"><span style=3D"font-size:11p=
t">=C2=A0</span></p>
                        <div style=3D"border-width:1pt medium medium;border=
-style:solid none none;border-color:rgb(181,196,223) currentcolor currentco=
lor;padding:3pt 0in 0in">
                          <p class=3D"MsoNormal"><b><span style=3D"font-fam=
ily:Calibri,sans-serif;color:black">From:
                              </span></b><span style=3D"font-family:Calibri=
,sans-serif;color:black">Mike Ounsworth &lt;<a href=3D"mailto:ounsworth%2Bi=
etf@gmail.com" target=3D"_blank">ounsworth+ietf@gmail.com</a>&gt;<br>
                              <b>Date: </b>Wednesday, October 29, 2025
                              at 11:11=E2=80=AFAM<br>
                              <b>To: </b>Eric Rescorla &lt;<a href=3D"mailt=
o:ekr@rtfm.com" target=3D"_blank">ekr@rtfm.com</a>&gt;<br>
                              <b>Cc: </b>LAMPS WG &lt;<a href=3D"mailto:spa=
sm@ietf.org" target=3D"_blank">spasm@ietf.org</a>&gt;,
                              CFRG &lt;<a href=3D"mailto:cfrg@irtf.org" tar=
get=3D"_blank">cfrg@irtf.org</a>&gt;,
                              &quot;<a href=3D"mailto:hpke@ietf.org" target=
=3D"_blank">hpke@ietf.org</a>&quot;
                              &lt;<a href=3D"mailto:hpke@ietf.org" target=
=3D"_blank">hpke@ietf.org</a>&gt;<br>
                              <b>Subject: </b>[CFRG] Re: New labels in
                              draft-irtf-cfrg-concrete-hybrid-kems-01</span=
></p>
                        </div>
                        <div>
                          <p class=3D"MsoNormal">=C2=A0</p>
                        </div>
                        <div style=3D"border:1pt solid rgb(0,70,121);paddin=
g:2pt">
                          <p class=3D"MsoNormal" style=3D"line-height:12pt;=
background:rgb(0,70,121)"><span style=3D"font-size:10pt;font-family:Calibri=
,sans-serif;color:yellow">NPS
                              WARNING: *external sender* verify before
                              acting.</span></p>
                        </div>
                        <p class=3D"MsoNormal">=C2=A0</p>
                        <div>
                          <div>
                            <div>
                              <p class=3D"MsoNormal">As as pointed out by
                                Daniel Van Geest in another thread, the
                                label for=C2=A0MLKEM1024-P384 is supposed t=
o
                                be &quot; | /-\&quot;, but in the published
                                version of the cfrg draft (both HTML and
                                TXT), it displays as=C2=A0` | /-` (note the
                                missing backslash). So that means that
                                the kramdown2rfc tooling is not handling
                                this properly.</p>
                            </div>
                            <div>
                              <p class=3D"MsoNormal">=C2=A0</p>
                            </div>
                            <div>
                              <p class=3D"MsoNormal">So when I said &quot;T=
his
                                is GOING to lead to at least
                                incompatibilities if not CVEs&quot; I didn&=
#39;t
                                realize that we already had one in the
                                draft.</p>
                            </div>
                            <div>
                              <p class=3D"MsoNormal">=C2=A0</p>
                            </div>
                            <div>
                              <p class=3D"MsoNormal">The point is this:</p>
                            </div>
                            <div>
                              <p class=3D"MsoNormal">The LAMPS doc is
                                already in WGLC (months later than we
                                wanted), using the labels from YOUR -00
                                (minus the SHAKE256 component). I made
                                that change in consultation with you
                                guys as part of the CRFC Interim in
                                Sept. Your doc is not in WGLC yet, so
                                can you please change your labels to
                                match?</p>
                            </div>
                          </div>
                          <p class=3D"MsoNormal">=C2=A0</p>
                          <div>
                            <div>
                              <p class=3D"MsoNormal">On Wed, 29 Oct 2025
                                at 12:47, Eric Rescorla &lt;<a href=3D"mail=
to:ekr@rtfm.com" target=3D"_blank">ekr@rtfm.com</a>&gt;
                                wrote:</p>
                            </div>
                            <blockquote style=3D"border-width:medium medium=
 medium 1pt;border-style:none none none solid;border-color:currentcolor cur=
rentcolor currentcolor rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left=
:4.8pt;margin-right:0in">
                              <div>
                                <div>
                                  <p class=3D"MsoNormal">I can&#39;t speak=
=C2=A0for
                                    what has or has not happened in
                                    terms of interop, but on the</p>
                                </div>
                                <div>
                                  <p class=3D"MsoNormal">substance of the
                                    labels I agree with Mike. I strongly
                                    prefer simple human-readable</p>
                                </div>
                                <div>
                                  <p class=3D"MsoNormal">labels to ASCII
                                    art Star Wars references, no matter
                                    how clever those references</p>
                                </div>
                                <div>
                                  <p class=3D"MsoNormal">might be.</p>
                                </div>
                                <div>
                                  <p class=3D"MsoNormal">=C2=A0</p>
                                </div>
                                <div>
                                  <p class=3D"MsoNormal">-Ekr</p>
                                </div>
                              </div>
                              <p class=3D"MsoNormal">=C2=A0</p>
                              <div>
                                <div>
                                  <p class=3D"MsoNormal">On Wed, Oct 29,
                                    2025 at 10:36<span style=3D"font-family=
:Arial,sans-serif">=E2=80=AF</span>AM Mike Ounsworth &lt;<a href=3D"mailto:=
ounsworth%2Bietf@gmail.com" target=3D"_blank">ounsworth+ietf@gmail.com</a>&=
gt;
                                    wrote:</p>
                                </div>
                                <blockquote style=3D"border-width:medium me=
dium medium 1pt;border-style:none none none solid;border-color:currentcolor=
 currentcolor currentcolor rgb(204,204,204);padding:0in 0in 0in 6pt;margin-=
left:4.8pt;margin-right:0in">
                                  <div>
                                    <div>
                                      <p class=3D"MsoNormal">draft-irtf-cfr=
g-concrete-hybrid-kems-01
                                        publish on Oct 20 and made the
                                        following label changes:</p>
                                    </div>
                                    <div>
                                      <p class=3D"MsoNormal">=C2=A0</p>
                                    </div>
                                    <div>
                                      <p class=3D"MsoNormal">=C2=A0</p>
                                    </div>
                                    <div>
                                      <p class=3D"MsoNormal">&quot;QSF-P256=
-MLKEM768-SHAKE256-SHA3256&quot;
                                        --&gt;=C2=A0 &quot;|-()-|&quot;</p>
                                    </div>
                                    <div>
                                      <p class=3D"MsoNormal">&quot;QSF-P384=
-MLKEM1024-SHAKE256-SHA3256&quot;
                                        --&gt; &quot; | /-&quot;</p>
                                    </div>
                                    <div>
                                      <p class=3D"MsoNormal"><br>
                                        <br>
                                        Please tell me this is a joke.
                                        Then please remove this from the
                                        draft and put the labels back to
                                        sane alphanumeric. I&#39;m sorry fo=
r
                                        strong language below, but this
                                        makes me mad.<br>
                                        <br>
                                        I have been bending over
                                        backwards to make the LAMPS
                                        thing match the HPKE thing,
                                        including multiple rounds of
                                        interop-testing against your
                                        test vectors and changing the
                                        LAMPS draft, reference impl, and
                                        test vectors to match yours.
                                        This has resulted in delayed
                                        publication of the LAMPS draft
                                        by several months to accommodate
                                        interop with the HPKE draft. The
                                        LAMPS Composite-KEM doc went
                                        into WGLC on Oct 17 now using
                                        HPKE-style labels of the form
                                        &quot;QSF-MLKEM768-P256-SHA3256&quo=
t; that
                                        we pulled FROM YOUR DRAFT
                                        instead of the OID-based labels
                                        we had before. Then on Oct 20
                                        you publish a new version that
                                        goes and changes the labels to
                                        this nonsense. Can you guys
                                        please at least pretend like you
                                        care about interop between these
                                        two docs?<br>
                                        <br>
                                        My specific objections to more
                                        ASCII art labels:<br>
                                        <br>
                                        1. We&#39;re already having interop
                                        problems at the PQC hackathon
                                        group because of the backslash
                                        in the xwing label -- for
                                        example, in python you have to
                                        put the constant in your source
                                        code as &quot;\\.//^\\&quot; to pre=
vent it
                                        from interpreting that as an
                                        escaped dot and double-quote.
                                        We&#39;ve also had similar problems
                                        representing this label properly
                                        in HTML and markdown docs. Now
                                        you want more labels that have
                                        both backslashes and now spaces.
                                        This is GOING to lead to at
                                        least incompatibilities if not
                                        CVEs.<br>
                                        <br>
                                        2. The label is not
                                        human-readable; it doesn&#39;t tell
                                        my anything=C2=A0useful about the
                                        content, nor will it be easy to
                                        debug mistakes in source code or
                                        config files. At this point,
                                        assigning a numeric codepoint
                                        would be preferable.<br>
                                        <br>
                                        3. This does not establish a
                                        naming convention that is easily
                                        extensible to other hybrid
                                        combinations.<br>
                                        <br>
                                        I have been doing everything in
                                        my power to work behind the
                                        scenes to get interop between
                                        these two documents, and it
                                        feels like you guys are doing
                                        everything in your power to
                                        obstruct it.</p>
                                    </div>
                                    <div>
                                      <p class=3D"MsoNormal"><br>
                                        Can you please put your labels
                                        back so that they match the
                                        LAMPS draft using the pattern
                                        &quot;QSF-MLKEM768-P256-SHA3256&quo=
t;.</p>
                                    </div>
                                    <div>
                                      <div>
                                        <p class=3D"MsoNormal"><span style=
=3D"color:rgb(136,136,136)">=C2=A0</span></p>
                                      </div>
                                      <div>
                                        <p class=3D"MsoNormal"><span style=
=3D"color:rgb(136,136,136)">(PS this is a re-send from the correct
                                            email address)</span></p>
                                      </div>
                                      <div>
                                        <p class=3D"MsoNormal"><span style=
=3D"color:rgb(136,136,136)"><br>
                                            -Mike</span></p>
                                      </div>
                                    </div>
                                  </div>
                                  <p class=3D"MsoNormal">__________________=
_____________________________<br>
                                    CFRG mailing list -- <a href=3D"mailto:=
cfrg@irtf.org" target=3D"_blank">cfrg@irtf.org</a><br>
                                    To unsubscribe send an email to <a href=
=3D"mailto:cfrg-leave@irtf.org" target=3D"_blank">
                                      cfrg-leave@irtf.org</a></p>
                                </blockquote>
                              </div>
                            </blockquote>
                          </div>
                        </div>
                      </div>
                    </div>
                    _______________________________________________<br>
                    hpke mailing list -- <a href=3D"mailto:hpke@ietf.org" t=
arget=3D"_blank">hpke@ietf.org</a><br>
                    To unsubscribe send an email to <a href=3D"mailto:hpke-=
leave@ietf.org" target=3D"_blank">hpke-leave@ietf.org</a><br>
                  </div>
                </blockquote>
              </div>
              <div><br clear=3D"all">
              </div>
              <div><br>
              </div>
              <span class=3D"gmail_signature_prefix">-- </span><br>
              <div dir=3D"ltr" class=3D"gmail_signature">
                <div dir=3D"ltr">
                  <div>
                    <div dir=3D"ltr">
                      <div>
                        <div dir=3D"ltr">
                          <div>
                            <div dir=3D"ltr">
                              <div>
                                <div dir=3D"ltr">
                                  <div style=3D"line-height:1.5em;padding-t=
op:10px;margin-top:10px;color:rgb(85,85,85);font-family:sans-serif;font-siz=
e:small"><span style=3D"border-width:2px 0px 0px;border-style:solid;border-=
color:rgb(213,15,37);padding-top:2px;margin-top:2px"><br>
                                      Sophie Schmieg=C2=A0|</span><span sty=
le=3D"border-width:2px 0px 0px;border-style:solid;border-color:rgb(51,105,2=
32);padding-top:2px;margin-top:2px">=C2=A0Information
                                      Security Engineer=C2=A0|</span><span =
style=3D"border-width:2px 0px 0px;border-style:solid;border-color:rgb(0,153=
,57);padding-top:2px;margin-top:2px">=C2=A0ISE
                                      Crypto=C2=A0|</span><span style=3D"bo=
rder-width:2px 0px 0px;border-style:solid;border-color:rgb(238,178,17);padd=
ing-top:2px;margin-top:2px">=C2=A0<a href=3D"mailto:sschmieg@google.com" ta=
rget=3D"_blank">sschmieg@google.com</a></span></div>
                                  <div><span style=3D"border-width:2px 0px =
0px;border-style:solid;border-color:rgb(238,178,17);padding-top:2px;margin-=
top:2px"><br>
                                    </span></div>
                                  <span style=3D"color:rgb(0,0,0);font-fami=
ly:&quot;Times New Roman&quot;;font-size:medium"></span></div>
                              </div>
                            </div>
                          </div>
                        </div>
                      </div>
                    </div>
                  </div>
                </div>
              </div>
            </blockquote>
          </div>
        </blockquote>
      </div>
      <br>
      <fieldset></fieldset>
      <pre>_______________________________________________
CFRG mailing list -- <a href=3D"mailto:cfrg@irtf.org" target=3D"_blank">cfr=
g@irtf.org</a>
To unsubscribe send an email to <a href=3D"mailto:cfrg-leave@irtf.org" targ=
et=3D"_blank">cfrg-leave@irtf.org</a>
</pre>
    </blockquote>
  </div>

_______________________________________________<br>
hpke mailing list -- <a href=3D"mailto:hpke@ietf.org" target=3D"_blank">hpk=
e@ietf.org</a><br>
To unsubscribe send an email to <a href=3D"mailto:hpke-leave@ietf.org" targ=
et=3D"_blank">hpke-leave@ietf.org</a><br>
</blockquote></div>

--000000000000d9646f0642527617--

