Return-Path: <ietf@dennis-jackson.uk>
X-Original-To: cfrg@mail2.ietf.org
Delivered-To: cfrg@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1])
	by mail2.ietf.org (Postfix) with ESMTP id 4E10F7ECF806
	for <cfrg@mail2.ietf.org>; Thu, 30 Oct 2025 04:19:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.798
X-Spam-Level: 
X-Spam-Status: No, score=-2.798 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001,
	RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001,
	RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001]
	autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key)
	header.d=dennis-jackson.uk
Received: from mail2.ietf.org ([166.84.6.31])
	by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id WlzPhZ0nz9gv for <cfrg@mail2.ietf.org>;
	Thu, 30 Oct 2025 04:19:22 -0700 (PDT)
Received: from mout-p-103.mailbox.org (mout-p-103.mailbox.org [80.241.56.161])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by mail2.ietf.org (Postfix) with ESMTPS id E69C47ECF7F6
	for <cfrg@irtf.org>; Thu, 30 Oct 2025 04:19:21 -0700 (PDT)
Received: from smtp2.mailbox.org (smtp2.mailbox.org [10.196.197.2])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest
 SHA256)
	(No client certificate requested)
	by mout-p-103.mailbox.org (Postfix) with ESMTPS id 4cy1pS2scJz9tCK;
	Thu, 30 Oct 2025 12:19:12 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dennis-jackson.uk;
	s=MBO0001; t=1761823152;
	h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
	 to:to:cc:cc:mime-version:mime-version:content-type:content-type:
	 in-reply-to:in-reply-to:references:references;
	bh=5MMY27oT1hxEQQSmEYWMU54AnTOx5/e/RT3MiQv1zyc=;
	b=J0I1fcEpqNgNJKcFyVVmsOyr9iD0skKWNQHLFzAl8AfzmGejcH9zWn5yJ/bXyUEYZ+MIxx
	sr4i3IQWSb+wkpN4vFsSz9iBV7VRgofJKcM9r5NYivwq1VeBFmhHGYtkrkSABgnxmIBe8J
	owHOAnD96CAoc81zTAl1s0wtyAwKnepMdCNSzX03gVFek2BbZ9NLVwtX4WOOg3ah+JhOW9
	CWEm4Y0BYP9E1wKkumNb2sgv+PiaadW4q+abQz5o1pQW/6LAJYig5ug59gVcN6bIlPQJNh
	/GdM8ePLFsrJtndQYl1xu/OnOYWhO71k12/1x4T7gXIt+3+eMMmUIutlUN8X5g==
Content-Type: multipart/alternative;
 boundary="------------3sW0WVXyJht1Z0QykpM0I1vE"
Message-ID: <243852fc-e0d4-4230-9238-b302c37b3ff7@dennis-jackson.uk>
Date: Thu, 30 Oct 2025 11:19:10 +0000
MIME-Version: 1.0
To: cfrg@irtf.org
References: 
 <CAKZgXHpQH7PcGiz9FxFCmr1hE29EGx9WuPDP-RFfem-2Bjyh6w@mail.gmail.com>
 <CABcZeBNR7TT6+fMPjdK7N-v6hWgLLHxhDw-D4qGhuOVfsUgqyw@mail.gmail.com>
 <CAKZgXHpW9PpuhUs=sS9Q8d1MMqEyWh8hp3khp2Vuryf3LANcLw@mail.gmail.com>
 <2D85ACB8-26D1-4E42-B4BE-DD5CD9BDE33A@nps.edu>
 <CAEEbLAZOjWigARX4nn+88qJ1cJomaGz6UTUepuaY3wddjpWSuw@mail.gmail.com>
 <CABcZeBN75WDp=g6Zd-vFm_B7mtrU0F97iA54RT98up=tFf_mKQ@mail.gmail.com>
 <CABcZeBOmNiJgT7QZS48t=oCk40cbwXcW8VA8wRf5h8kuo+gPuw@mail.gmail.com>
 <2eff0118-f6c9-4292-b28d-c12e7aefc358@dennis-jackson.uk>
 <CABcZeBPYbivNNsgYgMnrO7tSR7gyr=3wqLiQ1PYzySH-1uyQEg@mail.gmail.com>
Content-Language: en-US
From: Dennis Jackson <ietf@dennis-jackson.uk>
In-Reply-To: 
 <CABcZeBPYbivNNsgYgMnrO7tSR7gyr=3wqLiQ1PYzySH-1uyQEg@mail.gmail.com>
Message-ID-Hash: 6DWQEBQAN6CXXXILYGVIITVGUWFNVKMY
X-Message-ID-Hash: 6DWQEBQAN6CXXXILYGVIITVGUWFNVKMY
X-MailFrom: ietf@dennis-jackson.uk
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-cfrg.irtf.org-0;
 header-match-cfrg.irtf.org-1; nonmember-moderation; administrivia;
 implicit-dest; max-recipients; max-size; news-moderation; no-subject;
 digests; suspicious-header
CC: LAMPS <spasm@ietf.org>, hpke@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5BCFRG=5D_Re=3A_=5Blamps=5D_Re=3A_Re=3A_=5Bhpke=5D_Re=3A_Re=3A_Ne?=
 =?utf-8?q?w_labels_in_draft-irtf-cfrg-concrete-hybrid-kems-01?=
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/cfrg/ihy9dwPLMJdcImUtrbXRGzDMX6c>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Owner: <mailto:cfrg-owner@irtf.org>
List-Post: <mailto:cfrg@irtf.org>
List-Subscribe: <mailto:cfrg-join@irtf.org>
List-Unsubscribe: <mailto:cfrg-leave@irtf.org>

This is a multi-part message in MIME format.
--------------3sW0WVXyJht1Z0QykpM0I1vE
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

There is no technical argument here. I can't say I care for Star Wars 
either*, but all we need is some distinct hex strings. That's been 
accomplished:

>> 0x7C2D28292D7C for X-Wing
>> 0x5C2E2F2F5E5C for P256-ML-KEM1024
>> 0x207C202F2D5C for P384-ML-KEM1024
We should move on.

Best,
Dennis

* tbf Andor was pretty good.

On 29/10/2025 21:05, Eric Rescorla wrote:

>
>
> On Wed, Oct 29, 2025 at 2:03 PM Dennis Jackson 
> <ietf=40dennis-jackson.uk@dmarc.ietf.org> wrote:
>
>     My understanding is that the new labels in the CFRG draft were
>     chosen because nobody could agree on what human readable content
>     to include.
>
>     The timing around when the drafts landed & the communication
>     around the label change has made things messy and I totally get
>     the frustration there.
>
>     A pragmatic way forward would be to just use the hex and drop the
>     ASCII from the cfrg draft:
>
>>     0x7C2D28292D7C for X-Wing
>>     0x5C2E2F2F5E5C for P256-ML-KEM1024
>>     0x207C202F2D5C for P384-ML-KEM1024
>
>     These numbers are as good as any other and it paves over the
>     issues folks already ran into with the (unchangeable) X-Wing label.
>
>
> I don't agree that they're as good as any other. We should resist the
> urge to be clever when we don't have to, and "this hex string just
> happens to map to some piece of Star Wars inspired ASCII art"
> is, at least for me, in that category.
>
> -Ekr
>
>     Best,
>     Dennis
>
>     On 29/10/2025 20:43, Eric Rescorla wrote:
>>     Following up to myself.... I'm also fine with the LAMPS strings.
>>
>>     -Ekr
>>
>>
>>     On Wed, Oct 29, 2025 at 1:27 PM Eric Rescorla <ekr@rtfm.com> wrote:
>>
>>         I would make a few points here:
>>
>>         I don't have a strong opinion on whether we ought to have
>>         structured strings or just 6-byte constants but ISTM that
>>         having the spec contain strings which contain special
>>         characters are a clear safety hazard, and the only motivation
>>         for them seems to be to make a Star Wars joke, which really
>>         doesn't seem like a priority for the RG. That seems more like
>>         a bug than a feature to me. With that said, while the X-wing
>>         label is unfortunate, I don't think anyone is proposing to
>>         change it, but no such considerations exist for the other
>>         value. To that end, I propose the following:
>>
>>         - Render the labels only as hex values.
>>         - Replace the non-X-wing labels with values which don't
>>         happen to correspond to escape characters. The obvious thing
>>         to do here is just to use a simple counter, so we can use
>>         (x00...00 and 0x00..02) but I could imagine other approaches.
>>
>>         The net effect of these is to slightly reduce the surface
>>         area for errors without creating an interop problem or
>>         arguments about the semantics of the strings.
>>
>>         Finally, I would observe that arguments of the form "we need
>>         to get things out now so we need to do things the way I
>>         prefer" are less persuasive than "we need to get this now so
>>         I'm prepared to do things a way I don't really like".
>>
>>         -Ekr
>>
>>
>>
>>         On Wed, Oct 29, 2025 at 1:11 PM Sophie Schmieg
>>         <sschmieg@google.com> wrote:
>>
>>             The labels are simple numeric codepoints:
>>             0x7C2D28292D7C for X-Wing
>>             0x5C2E2F2F5E5C for P256-ML-KEM1024
>>             0x207C202F2D5C for P384-ML-KEM1024
>>             in little endian.
>>             And yes, I concur with Filippo, we need to be able to
>>             ship without being held up by discussions on naming
>>             things, and simple numerical values like the ones above
>>             allow us to do just that.
>>
>>             On Wed, Oct 29, 2025 at 12:17 PM Hale, Britta (CIV)
>>             <britta.hale=40nps.edu@dmarc.ietf.org> wrote:
>>
>>                 I concur with keeping clear and human-readable
>>                 ciphersuites (e.g.,
>>                 “QSF-P256-MLKEM768-SHAKE256-SHA3256”). Post quantum
>>                 migration is challenging enough without adding a
>>                 further mapping that humans can mis-interpret, which
>>                 can itself lead to introduction of vulnerabilities
>>                 while attempting use of post quantum algorithms.
>>
>>                 If there are any cases where shorthand is absolutely
>>                 needed (e.g., in specific WGs where counting bytes
>>                 matters), then reference strings ought to be simple
>>                 such as a numeric mapping to specific suites. ASCII
>>                 art makes it difficult to ensure correctness, even
>>                 among knowledgeable individuals, as is evident by the
>>                 examples already encountered. We should not be making
>>                 standards intentionally more difficult to follow for
>>                 less experienced individuals.
>>
>>                 Britta
>>
>>                 *From: *Mike Ounsworth <ounsworth+ietf@gmail.com
>>                 <mailto:ounsworth%2Bietf@gmail.com>>
>>                 *Date: *Wednesday, October 29, 2025 at 11:11 AM
>>                 *To: *Eric Rescorla <ekr@rtfm.com>
>>                 *Cc: *LAMPS WG <spasm@ietf.org>, CFRG
>>                 <cfrg@irtf.org>, "hpke@ietf.org" <hpke@ietf.org>
>>                 *Subject: *[CFRG] Re: New labels in
>>                 draft-irtf-cfrg-concrete-hybrid-kems-01
>>
>>                 NPS WARNING: *external sender* verify before acting.
>>
>>                 As as pointed out by Daniel Van Geest in another
>>                 thread, the label for MLKEM1024-P384 is supposed to
>>                 be " | /-\", but in the published version of the cfrg
>>                 draft (both HTML and TXT), it displays as ` | /-`
>>                 (note the missing backslash). So that means that the
>>                 kramdown2rfc tooling is not handling this properly.
>>
>>                 So when I said "This is GOING to lead to at least
>>                 incompatibilities if not CVEs" I didn't realize that
>>                 we already had one in the draft.
>>
>>                 The point is this:
>>
>>                 The LAMPS doc is already in WGLC (months later than
>>                 we wanted), using the labels from YOUR -00 (minus the
>>                 SHAKE256 component). I made that change in
>>                 consultation with you guys as part of the CRFC
>>                 Interim in Sept. Your doc is not in WGLC yet, so can
>>                 you please change your labels to match?
>>
>>                 On Wed, 29 Oct 2025 at 12:47, Eric Rescorla
>>                 <ekr@rtfm.com> wrote:
>>
>>                     I can't speak for what has or has not happened in
>>                     terms of interop, but on the
>>
>>                     substance of the labels I agree with Mike. I
>>                     strongly prefer simple human-readable
>>
>>                     labels to ASCII art Star Wars references, no
>>                     matter how clever those references
>>
>>                     might be.
>>
>>                     -Ekr
>>
>>                     On Wed, Oct 29, 2025 at 10:36 AM Mike Ounsworth
>>                     <ounsworth+ietf@gmail.com
>>                     <mailto:ounsworth%2Bietf@gmail.com>> wrote:
>>
>>                         draft-irtf-cfrg-concrete-hybrid-kems-01
>>                         publish on Oct 20 and made the following
>>                         label changes:
>>
>>                         "QSF-P256-MLKEM768-SHAKE256-SHA3256" --> 
>>                         "|-()-|"
>>
>>                         "QSF-P384-MLKEM1024-SHAKE256-SHA3256" --> " | /-"
>>
>>
>>
>>                         Please tell me this is a joke. Then please
>>                         remove this from the draft and put the labels
>>                         back to sane alphanumeric. I'm sorry for
>>                         strong language below, but this makes me mad.
>>
>>                         I have been bending over backwards to make
>>                         the LAMPS thing match the HPKE thing,
>>                         including multiple rounds of interop-testing
>>                         against your test vectors and changing the
>>                         LAMPS draft, reference impl, and test vectors
>>                         to match yours. This has resulted in delayed
>>                         publication of the LAMPS draft by several
>>                         months to accommodate interop with the HPKE
>>                         draft. The LAMPS Composite-KEM doc went into
>>                         WGLC on Oct 17 now using HPKE-style labels of
>>                         the form "QSF-MLKEM768-P256-SHA3256" that we
>>                         pulled FROM YOUR DRAFT instead of the
>>                         OID-based labels we had before. Then on Oct
>>                         20 you publish a new version that goes and
>>                         changes the labels to this nonsense. Can you
>>                         guys please at least pretend like you care
>>                         about interop between these two docs?
>>
>>                         My specific objections to more ASCII art labels:
>>
>>                         1. We're already having interop problems at
>>                         the PQC hackathon group because of the
>>                         backslash in the xwing label -- for example,
>>                         in python you have to put the constant in
>>                         your source code as "\\.//^\\" to prevent it
>>                         from interpreting that as an escaped dot and
>>                         double-quote. We've also had similar problems
>>                         representing this label properly in HTML and
>>                         markdown docs. Now you want more labels that
>>                         have both backslashes and now spaces. This is
>>                         GOING to lead to at least incompatibilities
>>                         if not CVEs.
>>
>>                         2. The label is not human-readable; it
>>                         doesn't tell my anything useful about the
>>                         content, nor will it be easy to debug
>>                         mistakes in source code or config files. At
>>                         this point, assigning a numeric codepoint
>>                         would be preferable.
>>
>>                         3. This does not establish a naming
>>                         convention that is easily extensible to other
>>                         hybrid combinations.
>>
>>                         I have been doing everything in my power to
>>                         work behind the scenes to get interop between
>>                         these two documents, and it feels like you
>>                         guys are doing everything in your power to
>>                         obstruct it.
>>
>>
>>                         Can you please put your labels back so that
>>                         they match the LAMPS draft using the pattern
>>                         "QSF-MLKEM768-P256-SHA3256".
>>
>>                         (PS this is a re-send from the correct email
>>                         address)
>>
>>
>>                         -Mike
>>
>>                         _______________________________________________
>>                         CFRG mailing list -- cfrg@irtf.org
>>                         To unsubscribe send an email to
>>                         cfrg-leave@irtf.org
>>
>>                 _______________________________________________
>>                 hpke mailing list -- hpke@ietf.org
>>                 To unsubscribe send an email to hpke-leave@ietf.org
>>
>>
>>
>>             -- 
>>
>>             Sophie Schmieg | Information Security Engineer | ISE
>>             Crypto |sschmieg@google.com
>>
>>
>>     _______________________________________________
>>     CFRG mailing list --cfrg@irtf.org
>>     To unsubscribe send an email tocfrg-leave@irtf.org
>     _______________________________________________
>     Spasm mailing list -- spasm@ietf.org
>     To unsubscribe send an email to spasm-leave@ietf.org
>
--------------3sW0WVXyJht1Z0QykpM0I1vE
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>There is no technical argument here. I can't say I care for Star
      Wars either*, but all we need is some distinct hex strings. That's
      been accomplished:</p>
    <p>
      <blockquote type="cite">
        <blockquote type="cite">
          <div>0x7C2D28292D7C for X-Wing</div>
          <div>0x5C2E2F2F5E5C for P256-ML-KEM1024</div>
          <div>0x207C202F2D5C for P384-ML-KEM1024</div>
        </blockquote>
      </blockquote>
      We should move on.</p>
    <p>Best,<br>
      Dennis</p>
    <p>* tbf Andor was pretty good.  </p>
    <p>On 29/10/2025 21:05, Eric Rescorla wrote:</p>
    <blockquote type="cite"
cite="mid:CABcZeBPYbivNNsgYgMnrO7tSR7gyr=3wqLiQ1PYzySH-1uyQEg@mail.gmail.com">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div dir="ltr">
        <div dir="ltr"><br>
        </div>
        <br>
        <div class="gmail_quote gmail_quote_container">
          <div dir="ltr" class="gmail_attr">On Wed, Oct 29, 2025 at
            2:03 PM Dennis Jackson &lt;ietf=<a
              href="mailto:40dennis-jackson.uk@dmarc.ietf.org"
              moz-do-not-send="true" class="moz-txt-link-freetext">40dennis-jackson.uk@dmarc.ietf.org</a>&gt;
            wrote:<br>
          </div>
          <blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
            <div>
              <p>My understanding is that the new labels in the CFRG
                draft were chosen because nobody could agree on what
                human readable content to include. </p>
              <p>The timing around when the drafts landed &amp; the
                communication around the label change has made things
                messy and I totally get the frustration there.</p>
              <p>A pragmatic way forward would be to just use the hex
                and drop the ASCII from the cfrg draft:</p>
              <p> </p>
              <blockquote type="cite">
                <div>0x7C2D28292D7C for X-Wing</div>
                <div>0x5C2E2F2F5E5C for P256-ML-KEM1024</div>
                <div>0x207C202F2D5C for P384-ML-KEM1024</div>
              </blockquote>
              <p>These numbers are as good as any other and it paves
                over the issues folks already ran into with the
                (unchangeable) X-Wing label.</p>
            </div>
          </blockquote>
          <div><br>
          </div>
          <div>I don't agree that they're as good as any other. We
            should resist the</div>
          <div>urge to be clever when we don't have to, and "this hex
            string just</div>
          <div>happens to map to some piece of Star Wars inspired ASCII
            art"</div>
          <div>is, at least for me, in that category.</div>
          <div><br>
          </div>
          <div>-Ekr</div>
          <div><br>
          </div>
          <blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
            <div>
              <p>Best,<br>
                Dennis</p>
              <div>On 29/10/2025 20:43, Eric Rescorla wrote:<br>
              </div>
              <blockquote type="cite">
                <div dir="ltr">
                  <div>Following up to myself.... I'm also fine with the
                    LAMPS strings.</div>
                  <div><br>
                  </div>
                  <div>-Ekr</div>
                  <div><br>
                  </div>
                </div>
                <br>
                <div class="gmail_quote">
                  <div dir="ltr" class="gmail_attr">On Wed, Oct 29, 2025
                    at 1:27 PM Eric Rescorla &lt;<a
                      href="mailto:ekr@rtfm.com" target="_blank"
                      moz-do-not-send="true"
                      class="moz-txt-link-freetext">ekr@rtfm.com</a>&gt;
                    wrote:<br>
                  </div>
                  <blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
                    <div dir="ltr">
                      <div>I would make a few points here:</div>
                      <div><br>
                      </div>
                      <div>I don't have a strong opinion on whether we
                        ought to have structured strings or just 6-byte
                        constants but ISTM that having the spec contain
                        strings which contain special characters are a
                        clear safety hazard, and the only motivation for
                        them seems to be to make a Star Wars joke, which
                        really doesn't seem like a priority for the RG.
                        That seems more like a bug than a feature to me.
                        With that said, while the X-wing label is
                        unfortunate, I don't think anyone is proposing
                        to change it, but no such considerations exist
                        for the other value. To that end, I propose the
                        following:</div>
                      <div><br>
                      </div>
                      <div>- Render the labels only as hex values.</div>
                      <div>- Replace the non-X-wing labels with values
                        which don't happen to correspond to escape
                        characters. The obvious thing to do here is just
                        to use a simple counter, so we can use (x00...00
                        and 0x00..02) but I could imagine other
                        approaches.</div>
                      <div><br>
                      </div>
                      <div>The net effect of these is to slightly reduce
                        the surface area for errors without creating an
                        interop problem or arguments about the semantics
                        of the strings. </div>
                      <div><br>
                      </div>
                      <div>Finally, I would observe that arguments of
                        the form "we need to get things out now so we
                        need to do things the way I prefer" are less
                        persuasive than "we need to get this now so I'm
                        prepared to do things a way I don't really
                        like".</div>
                      <div><br>
                      </div>
                      <div>-Ekr</div>
                      <div><br>
                      </div>
                      <div><br>
                      </div>
                    </div>
                    <br>
                    <div class="gmail_quote">
                      <div dir="ltr" class="gmail_attr">On Wed, Oct 29,
                        2025 at 1:11 PM Sophie Schmieg &lt;<a
                          href="mailto:sschmieg@google.com"
                          target="_blank" moz-do-not-send="true"
                          class="moz-txt-link-freetext">sschmieg@google.com</a>&gt;
                        wrote:<br>
                      </div>
                      <blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
                        <div dir="ltr">The labels are simple numeric
                          codepoints:
                          <div>0x7C2D28292D7C for X-Wing</div>
                          <div>0x5C2E2F2F5E5C for P256-ML-KEM1024</div>
                          <div>0x207C202F2D5C for P384-ML-KEM1024</div>
                          <div>in little endian.</div>
                          <div>And yes, I concur with Filippo, we need
                            to be able to ship without being held up by
                            discussions on naming things, and simple
                            numerical values like the ones above allow
                            us to do just that.</div>
                        </div>
                        <br>
                        <div class="gmail_quote">
                          <div dir="ltr" class="gmail_attr">On Wed, Oct
                            29, 2025 at 12:17 PM Hale, Britta (CIV)
                            &lt;britta.hale=<a
                              href="mailto:40nps.edu@dmarc.ietf.org"
                              target="_blank" moz-do-not-send="true"
                              class="moz-txt-link-freetext">40nps.edu@dmarc.ietf.org</a>&gt;
                            wrote:<br>
                          </div>
                          <blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
                            <div>
                              <div lang="EN-US">
                                <div>
                                  <div>
                                    <p class="MsoNormal"><span
                                        style="font-size:11pt">I concur
                                        with keeping clear and
                                        human-readable ciphersuites
                                        (e.g.,
                                        “QSF-P256-MLKEM768-SHAKE256-SHA3256”).
                                        Post quantum migration is
                                        challenging enough without
                                        adding a further mapping that
                                        humans can mis-interpret, which
                                        can itself lead to introduction
                                        of vulnerabilities while
                                        attempting use of post quantum
                                        algorithms. </span></p>
                                    <p class="MsoNormal"><span
                                        style="font-size:11pt"> </span></p>
                                    <p class="MsoNormal"><span
                                        style="font-size:11pt">If there
                                        are any cases where shorthand is
                                        absolutely needed (e.g., in
                                        specific WGs where counting
                                        bytes matters), then reference
                                        strings ought to be simple such
                                        as a numeric mapping to specific
                                        suites. ASCII art makes it
                                        difficult to ensure correctness,
                                        even among knowledgeable
                                        individuals, as is evident by
                                        the examples already
                                        encountered. We should not be
                                        making standards intentionally
                                        more difficult to follow for
                                        less experienced individuals. </span></p>
                                    <p class="MsoNormal"><span
                                        style="font-size:11pt"> </span></p>
                                    <p class="MsoNormal"><span
                                        style="font-size:11pt">Britta</span></p>
                                  </div>
                                  <p class="MsoNormal"><span
                                      style="font-size:11pt"> </span></p>
                                  <p class="MsoNormal"><span
                                      style="font-size:11pt"> </span></p>
                                  <div
style="border-width:1pt medium medium;border-style:solid none none;border-color:rgb(181,196,223) currentcolor currentcolor;padding:3pt 0in 0in">
                                    <p class="MsoNormal"><b><span
style="font-family:Calibri,sans-serif;color:black">From: </span></b><span
style="font-family:Calibri,sans-serif;color:black">Mike Ounsworth &lt;<a
href="mailto:ounsworth%2Bietf@gmail.com" target="_blank"
                                          moz-do-not-send="true">ounsworth+ietf@gmail.com</a>&gt;<br>
                                        <b>Date: </b>Wednesday, October
                                        29, 2025 at 11:11 AM<br>
                                        <b>To: </b>Eric Rescorla &lt;<a
                                          href="mailto:ekr@rtfm.com"
                                          target="_blank"
                                          moz-do-not-send="true"
                                          class="moz-txt-link-freetext">ekr@rtfm.com</a>&gt;<br>
                                        <b>Cc: </b>LAMPS WG &lt;<a
                                          href="mailto:spasm@ietf.org"
                                          target="_blank"
                                          moz-do-not-send="true"
                                          class="moz-txt-link-freetext">spasm@ietf.org</a>&gt;,
                                        CFRG &lt;<a
                                          href="mailto:cfrg@irtf.org"
                                          target="_blank"
                                          moz-do-not-send="true"
                                          class="moz-txt-link-freetext">cfrg@irtf.org</a>&gt;,
                                        "<a href="mailto:hpke@ietf.org"
                                          target="_blank"
                                          moz-do-not-send="true"
                                          class="moz-txt-link-freetext">hpke@ietf.org</a>"
                                        &lt;<a
                                          href="mailto:hpke@ietf.org"
                                          target="_blank"
                                          moz-do-not-send="true"
                                          class="moz-txt-link-freetext">hpke@ietf.org</a>&gt;<br>
                                        <b>Subject: </b>[CFRG] Re: New
                                        labels in
                                        draft-irtf-cfrg-concrete-hybrid-kems-01</span></p>
                                  </div>
                                  <div>
                                    <p class="MsoNormal"> </p>
                                  </div>
                                  <div
style="border:1pt solid rgb(0,70,121);padding:2pt">
                                    <p class="MsoNormal"
style="line-height:12pt;background:rgb(0,70,121)"><span
style="font-size:10pt;font-family:Calibri,sans-serif;color:yellow">NPS
                                        WARNING: *external sender*
                                        verify before acting.</span></p>
                                  </div>
                                  <p class="MsoNormal"> </p>
                                  <div>
                                    <div>
                                      <div>
                                        <p class="MsoNormal">As as
                                          pointed out by Daniel Van
                                          Geest in another thread, the
                                          label for MLKEM1024-P384 is
                                          supposed to be " | /-\", but
                                          in the published version of
                                          the cfrg draft (both HTML and
                                          TXT), it displays as ` | /-`
                                          (note the missing backslash).
                                          So that means that the
                                          kramdown2rfc tooling is not
                                          handling this properly.</p>
                                      </div>
                                      <div>
                                        <p class="MsoNormal"> </p>
                                      </div>
                                      <div>
                                        <p class="MsoNormal">So when I
                                          said "This is GOING to lead to
                                          at least incompatibilities if
                                          not CVEs" I didn't realize
                                          that we already had one in the
                                          draft.</p>
                                      </div>
                                      <div>
                                        <p class="MsoNormal"> </p>
                                      </div>
                                      <div>
                                        <p class="MsoNormal">The point
                                          is this:</p>
                                      </div>
                                      <div>
                                        <p class="MsoNormal">The LAMPS
                                          doc is already in WGLC (months
                                          later than we wanted), using
                                          the labels from YOUR -00
                                          (minus the SHAKE256
                                          component). I made that change
                                          in consultation with you guys
                                          as part of the CRFC Interim in
                                          Sept. Your doc is not in WGLC
                                          yet, so can you please change
                                          your labels to match?</p>
                                      </div>
                                    </div>
                                    <p class="MsoNormal"> </p>
                                    <div>
                                      <div>
                                        <p class="MsoNormal">On Wed, 29
                                          Oct 2025 at 12:47, Eric
                                          Rescorla &lt;<a
                                            href="mailto:ekr@rtfm.com"
                                            target="_blank"
                                            moz-do-not-send="true"
class="moz-txt-link-freetext">ekr@rtfm.com</a>&gt; wrote:</p>
                                      </div>
                                      <blockquote
style="border-width:medium medium medium 1pt;border-style:none none none solid;border-color:currentcolor currentcolor currentcolor rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
                                        <div>
                                          <div>
                                            <p class="MsoNormal">I can't
                                              speak for what has or has
                                              not happened in terms of
                                              interop, but on the</p>
                                          </div>
                                          <div>
                                            <p class="MsoNormal">substance
                                              of the labels I agree with
                                              Mike. I strongly prefer
                                              simple human-readable</p>
                                          </div>
                                          <div>
                                            <p class="MsoNormal">labels
                                              to ASCII art Star Wars
                                              references, no matter how
                                              clever those references</p>
                                          </div>
                                          <div>
                                            <p class="MsoNormal">might
                                              be.</p>
                                          </div>
                                          <div>
                                            <p class="MsoNormal"> </p>
                                          </div>
                                          <div>
                                            <p class="MsoNormal">-Ekr</p>
                                          </div>
                                        </div>
                                        <p class="MsoNormal"> </p>
                                        <div>
                                          <div>
                                            <p class="MsoNormal">On Wed,
                                              Oct 29, 2025 at 10:36<span
style="font-family:Arial,sans-serif"> </span>AM Mike Ounsworth &lt;<a
href="mailto:ounsworth%2Bietf@gmail.com" target="_blank"
                                                moz-do-not-send="true">ounsworth+ietf@gmail.com</a>&gt;
                                              wrote:</p>
                                          </div>
                                          <blockquote
style="border-width:medium medium medium 1pt;border-style:none none none solid;border-color:currentcolor currentcolor currentcolor rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
                                            <div>
                                              <div>
                                                <p class="MsoNormal">draft-irtf-cfrg-concrete-hybrid-kems-01
                                                  publish on Oct 20 and
                                                  made the following
                                                  label changes:</p>
                                              </div>
                                              <div>
                                                <p class="MsoNormal"> </p>
                                              </div>
                                              <div>
                                                <p class="MsoNormal"> </p>
                                              </div>
                                              <div>
                                                <p class="MsoNormal">"QSF-P256-MLKEM768-SHAKE256-SHA3256"
                                                  --&gt;  "|-()-|"</p>
                                              </div>
                                              <div>
                                                <p class="MsoNormal">"QSF-P384-MLKEM1024-SHAKE256-SHA3256"
                                                  --&gt; " | /-"</p>
                                              </div>
                                              <div>
                                                <p class="MsoNormal"><br>
                                                  <br>
                                                  Please tell me this is
                                                  a joke. Then please
                                                  remove this from the
                                                  draft and put the
                                                  labels back to sane
                                                  alphanumeric. I'm
                                                  sorry for strong
                                                  language below, but
                                                  this makes me mad.<br>
                                                  <br>
                                                  I have been bending
                                                  over backwards to make
                                                  the LAMPS thing match
                                                  the HPKE thing,
                                                  including multiple
                                                  rounds of
                                                  interop-testing
                                                  against your test
                                                  vectors and changing
                                                  the LAMPS draft,
                                                  reference impl, and
                                                  test vectors to match
                                                  yours. This has
                                                  resulted in delayed
                                                  publication of the
                                                  LAMPS draft by several
                                                  months to accommodate
                                                  interop with the HPKE
                                                  draft. The LAMPS
                                                  Composite-KEM doc went
                                                  into WGLC on Oct 17
                                                  now using HPKE-style
                                                  labels of the form
                                                  "QSF-MLKEM768-P256-SHA3256"
                                                  that we pulled FROM
                                                  YOUR DRAFT instead of
                                                  the OID-based labels
                                                  we had before. Then on
                                                  Oct 20 you publish a
                                                  new version that goes
                                                  and changes the labels
                                                  to this nonsense. Can
                                                  you guys please at
                                                  least pretend like you
                                                  care about interop
                                                  between these two
                                                  docs?<br>
                                                  <br>
                                                  My specific objections
                                                  to more ASCII art
                                                  labels:<br>
                                                  <br>
                                                  1. We're already
                                                  having interop
                                                  problems at the PQC
                                                  hackathon group
                                                  because of the
                                                  backslash in the xwing
                                                  label -- for example,
                                                  in python you have to
                                                  put the constant in
                                                  your source code as
                                                  "\\.//^\\" to prevent
                                                  it from interpreting
                                                  that as an escaped dot
                                                  and double-quote.
                                                  We've also had similar
                                                  problems representing
                                                  this label properly in
                                                  HTML and markdown
                                                  docs. Now you want
                                                  more labels that have
                                                  both backslashes and
                                                  now spaces. This is
                                                  GOING to lead to at
                                                  least
                                                  incompatibilities if
                                                  not CVEs.<br>
                                                  <br>
                                                  2. The label is not
                                                  human-readable; it
                                                  doesn't tell my
                                                  anything useful about
                                                  the content, nor will
                                                  it be easy to debug
                                                  mistakes in source
                                                  code or config files.
                                                  At this point,
                                                  assigning a numeric
                                                  codepoint would be
                                                  preferable.<br>
                                                  <br>
                                                  3. This does not
                                                  establish a naming
                                                  convention that is
                                                  easily extensible to
                                                  other hybrid
                                                  combinations.<br>
                                                  <br>
                                                  I have been doing
                                                  everything in my power
                                                  to work behind the
                                                  scenes to get interop
                                                  between these two
                                                  documents, and it
                                                  feels like you guys
                                                  are doing everything
                                                  in your power to
                                                  obstruct it.</p>
                                              </div>
                                              <div>
                                                <p class="MsoNormal"><br>
                                                  Can you please put
                                                  your labels back so
                                                  that they match the
                                                  LAMPS draft using the
                                                  pattern
                                                  "QSF-MLKEM768-P256-SHA3256".</p>
                                              </div>
                                              <div>
                                                <div>
                                                  <p class="MsoNormal"><span
style="color:rgb(136,136,136)"> </span></p>
                                                </div>
                                                <div>
                                                  <p class="MsoNormal"><span
style="color:rgb(136,136,136)">(PS this is a re-send from the correct
                                                      email address)</span></p>
                                                </div>
                                                <div>
                                                  <p class="MsoNormal"><span
style="color:rgb(136,136,136)"><br>
                                                      -Mike</span></p>
                                                </div>
                                              </div>
                                            </div>
                                            <p class="MsoNormal">_______________________________________________<br>
                                              CFRG mailing list -- <a
href="mailto:cfrg@irtf.org" target="_blank" moz-do-not-send="true"
class="moz-txt-link-freetext">cfrg@irtf.org</a><br>
                                              To unsubscribe send an
                                              email to <a
href="mailto:cfrg-leave@irtf.org" target="_blank" moz-do-not-send="true"
class="moz-txt-link-freetext"> cfrg-leave@irtf.org</a></p>
                                          </blockquote>
                                        </div>
                                      </blockquote>
                                    </div>
                                  </div>
                                </div>
                              </div>
_______________________________________________<br>
                              hpke mailing list -- <a
                                href="mailto:hpke@ietf.org"
                                target="_blank" moz-do-not-send="true"
                                class="moz-txt-link-freetext">hpke@ietf.org</a><br>
                              To unsubscribe send an email to <a
                                href="mailto:hpke-leave@ietf.org"
                                target="_blank" moz-do-not-send="true"
                                class="moz-txt-link-freetext">hpke-leave@ietf.org</a><br>
                            </div>
                          </blockquote>
                        </div>
                        <div><br clear="all">
                        </div>
                        <div><br>
                        </div>
                        <span class="gmail_signature_prefix">-- </span><br>
                        <div dir="ltr" class="gmail_signature">
                          <div dir="ltr">
                            <div>
                              <div dir="ltr">
                                <div>
                                  <div dir="ltr">
                                    <div>
                                      <div dir="ltr">
                                        <div>
                                          <div dir="ltr">
                                            <div
style="line-height:1.5em;padding-top:10px;margin-top:10px;color:rgb(85,85,85);font-family:sans-serif;font-size:small"><span
style="border-width:2px 0px 0px;border-style:solid;border-color:rgb(213,15,37);padding-top:2px;margin-top:2px"><br>
                                                Sophie Schmieg |</span><span
style="border-width:2px 0px 0px;border-style:solid;border-color:rgb(51,105,232);padding-top:2px;margin-top:2px"> Information
                                                Security Engineer |</span><span
style="border-width:2px 0px 0px;border-style:solid;border-color:rgb(0,153,57);padding-top:2px;margin-top:2px"> ISE
                                                Crypto |</span><span
style="border-width:2px 0px 0px;border-style:solid;border-color:rgb(238,178,17);padding-top:2px;margin-top:2px"> <a
href="mailto:sschmieg@google.com" target="_blank" moz-do-not-send="true"
class="moz-txt-link-freetext">sschmieg@google.com</a></span></div>
                                            <div><span
style="border-width:2px 0px 0px;border-style:solid;border-color:rgb(238,178,17);padding-top:2px;margin-top:2px"><br>
                                              </span></div>
                                            <span
style="color:rgb(0,0,0);font-family:&quot;Times New Roman&quot;;font-size:medium"></span></div>
                                        </div>
                                      </div>
                                    </div>
                                  </div>
                                </div>
                              </div>
                            </div>
                          </div>
                        </div>
                      </blockquote>
                    </div>
                  </blockquote>
                </div>
                <br>
                <fieldset></fieldset>
                <pre>_______________________________________________
CFRG mailing list -- <a href="mailto:cfrg@irtf.org" target="_blank"
                moz-do-not-send="true" class="moz-txt-link-freetext">cfrg@irtf.org</a>
To unsubscribe send an email to <a href="mailto:cfrg-leave@irtf.org"
                target="_blank" moz-do-not-send="true"
                class="moz-txt-link-freetext">cfrg-leave@irtf.org</a>
</pre>
              </blockquote>
            </div>
            _______________________________________________<br>
            Spasm mailing list -- <a href="mailto:spasm@ietf.org"
              target="_blank" moz-do-not-send="true"
              class="moz-txt-link-freetext">spasm@ietf.org</a><br>
            To unsubscribe send an email to <a
              href="mailto:spasm-leave@ietf.org" target="_blank"
              moz-do-not-send="true" class="moz-txt-link-freetext">spasm-leave@ietf.org</a><br>
          </blockquote>
        </div>
      </div>
    </blockquote>
  </body>
</html>

--------------3sW0WVXyJht1Z0QykpM0I1vE--

