Re: [CFRG] NSA vs. hybrid

Loganaden Velvindron <loganaden@gmail.com> Sun, 14 November 2021 05:34 UTC

Return-Path: <loganaden@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CE9363A091C for <cfrg@ietfa.amsl.com>; Sat, 13 Nov 2021 21:34:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0KzVNCkNKjju for <cfrg@ietfa.amsl.com>; Sat, 13 Nov 2021 21:34:13 -0800 (PST)
Received: from mail-qt1-x82d.google.com (mail-qt1-x82d.google.com [IPv6:2607:f8b0:4864:20::82d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C7C293A0913 for <cfrg@irtf.org>; Sat, 13 Nov 2021 21:34:13 -0800 (PST)
Received: by mail-qt1-x82d.google.com with SMTP id f20so12161102qtb.4 for <cfrg@irtf.org>; Sat, 13 Nov 2021 21:34:13 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=3WvAA98VXzXuNx7yAw2TnGzgDCnzvXX++Qd9VVOtfKs=; b=G54K102QvfJhBI1jTK1cxVqIN/s3LnKkfUNvbdUCQqGfuIa7Ut/PhneuMd6wKErRBl Teo0GSoiZqCRlNAXdC5WPE4EbZEGFxPvY6RmIgBk+kWehE2V+8VPdyJN0lfID+1cUP8N 2X9/Xj6M2DcOovDeeJHZWZyVkJINJ3/+qMdaezl5UubJsDoUAG0y8H/b7Mq+8VaQoNad HaQun1EZECjxfzKgIPZkaXPYzbdq3eZbGEE9JVzFZqWUUW8C8nHNwuk2x794d7XJ879e SyK9bhguAajPQ990MG9ZNfK17cUezkpq+N/YCuDsAmO7tYFWKIUhS03w8nhjI5+hPWoK Hejw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=3WvAA98VXzXuNx7yAw2TnGzgDCnzvXX++Qd9VVOtfKs=; b=OXHeC3+Qsk+Yf1Czi9giT2brjTkmvkjrBnJVXShp24Rz0Lq8PUhMqTngCuOrW9gZaR L/hPmFMKtfg5m/HyWl5JNrgE728Z2Yqg6CoM27cNBtkhighrUM0K4IC/C76e1ApoEA1U aUeuNJdMs1b75gOxmDqbwHtwCyAi8DvfwjOKY9lrMjnMi6ik9RpZkF1NSZu3xy3mB4xG jmrb5VXg+KdtvY4+qCm+nxIrg5p0+q8e6TjTfuSqxzBhPPUUEO11wXzk5UYqK/x0livV uJGMwJXOM5lDuRV8QNN07V/mbKR5mHU7Cc1HYtSVu5arW0vSJtsCc34Jk/JcvhkBlj1c AjJQ==
X-Gm-Message-State: AOAM530K12270+lJh6HZiXjAUOx9pV0xqBIcfsdXRxeX0k10AbEjJCHF oA5fewvO15BcHZ9rlp96kJWV3OD3Gc+4WzIcYIgOoVFq
X-Google-Smtp-Source: ABdhPJzI3mPXU+OeCPOMoYarrKITYDetPkdzic9damNfnalhVW6+WXzxSU1hIyuyqiWyp6/OBeMhk16JbdMW8TUuvAc=
X-Received: by 2002:a05:622a:189:: with SMTP id s9mr2537376qtw.352.1636868050113; Sat, 13 Nov 2021 21:34:10 -0800 (PST)
MIME-Version: 1.0
References: <20211113135339.770521.qmail@cr.yp.to> <9cffc5cd-a844-7311-6fd9-80691b4b10e6@cs.tcd.ie>
In-Reply-To: <9cffc5cd-a844-7311-6fd9-80691b4b10e6@cs.tcd.ie>
From: Loganaden Velvindron <loganaden@gmail.com>
Date: Sun, 14 Nov 2021 09:33:58 +0400
Message-ID: <CAOp4FwRWrMxbMXcNqJ2jnzdKY4_sUJKbWT47Qaw58p=asUm-Yw@mail.gmail.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Cc: CFRG <cfrg@irtf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/tYRrMPuABAmv5aFQ53kdGCntqCA>
Subject: Re: [CFRG] NSA vs. hybrid
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Sun, 14 Nov 2021 05:34:19 -0000

I also tend to agree with Dr Bernstein's points. I hope to see more
transparency in the process.

On Sat, Nov 13, 2021 at 6:57 PM Stephen Farrell
<stephen.farrell@cs.tcd.ie> wrote:
>
>
> Hiya,
>
> I think I'm in general agreement with djb on this. One note
> though...
>
> On 13/11/2021 13:53, D. J. Bernstein wrote:
> > I agree that certificate validation is a mess.
>
> For protocols like TLS (likely to remain the most important
> for quite a while) I don't think we need care about changes
> to the web PKI for a much longer while. Maybe we should add
> some PQC algorithm into some TLS handshakes soon, but there
> is no need to change the PKI for that in the same timeframe.
>
> In general, I'd be for slowing down much of this transition
> stuff, and having CFRG opine to that effect might be a good
> thing.
>
> Cheers,
> S.
>
> _______________________________________________
> CFRG mailing list
> CFRG@irtf.org
> https://www.irtf.org/mailman/listinfo/cfrg