[MLS] Thoughts on draft-ietf-mls-pq-ciphersuites
Soatok Dreamseeker <soatok.dhole@gmail.com> Fri, 10 April 2026 15:11 UTC
Return-Path: <soatok.dhole@gmail.com>
X-Original-To: mls@mail2.ietf.org
Delivered-To: mls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A5C8FD98C5B7 for <mls@mail2.ietf.org>; Fri, 10 Apr 2026 08:11:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775833877; bh=9wgIdQzNsTtSIOf26ZQoTQgtjXZGJSTYrIbUSOm0/Hk=; h=From:Date:Subject:To; b=ODZacDwEGF3gHHoAPLrbi4gCQ2CF0lJrV0zCCU9Wl+00VhUqzW2BVkCF91QU/DmCA 7Zpd7OCDDCCyn4tsoY45P+a3pNbhkD9VpE9PUSdqf6vRvfPr1RCR/NEVQNK1qEO64v MvBpV++S2I14awqESrJMd/jXNgh7ryh3nF90RLhU=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uHKtt-br4C3Y for <mls@mail2.ietf.org>; Fri, 10 Apr 2026 08:11:16 -0700 (PDT)
Received: from mail-yx1-xb136.google.com (mail-yx1-xb136.google.com [IPv6:2607:f8b0:4864:20::b136]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5FCC4D98C3F8 for <mls@ietf.org>; Fri, 10 Apr 2026 08:10:59 -0700 (PDT)
Received: by mail-yx1-xb136.google.com with SMTP id 956f58d0204a3-650775f427eso2209972d50.2 for <mls@ietf.org>; Fri, 10 Apr 2026 08:10:59 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1775833853; cv=none; d=google.com; s=arc-20240605; b=SIFplcP8eDecRYEqVZVDnDf1K9GexbtqtnC2CzJGikkqBEtNVidRL9DTLda39isIs0 jt0gg/tKGX8eptRueLM8bIYspCBjvZc8nYuUGOWM2DLoNlYSGKDO68SG54lg18T8843g XyO+YqasIJkZPPCxkrWoZNV/0G0B1VYsv58qY6wSNTyYcdo89V9tvVoWZm38LdW4Pi7I dmYlLabQcKfgdzAwnDbbiEp0iVsnnodMtXVhQLkhBlwY+C1+1xtgXguvcjhkD4E9Ocuo bCMWYjhNcdOtUxEFZX7LittmfTxENwuQi5YTkFm5AG1ddCvwg0n4LWYlpT2NVYdA8z5C XWhg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=8AOxuPm95TBFyiaLlqzqvHqB5PlfertzN1d5++9g3zs=; fh=dg9DVhWhWDo81XIC1gayXSFT3euwR2o8HQ200iRcuh4=; b=bccLnZiernvj6xzt7OEJp+A9G/JvG94Dtn3qr6xDRgaDXJIf/zWgrZCSz36lcgkdqF uovGuR1urOBhqgPYG5uXD6MZZzfgwOKT2lvVd50NpNjzDjRcheRMOQBhIrJgud0ZsB1C icvt/rAPilDzkAbAuMoZv1ThbXNDcCz4g3WeEEHzCE7f13qu1gTIDZMkfyD+PgTfkD6i 92S2QtM5S7NIe+WdUQ8H+9zeIHLyQXN6ruWr2X/vBpDIZkgVyXL/W8gw9HBdAtnIGa7d DQMq7qlHhLwgz0wDuzhv/m2TrGkBVIVHAu3QE3MTO4Zm7IFps4wXW/0pilDgAdleRAhD j+tg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1775833853; x=1776438653; darn=ietf.org; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=8AOxuPm95TBFyiaLlqzqvHqB5PlfertzN1d5++9g3zs=; b=HRrwciTRG9IXO8kq0SiA+DeDBw33pYazWZQZTOqjuef+qNpZzkHTKBtNb4A3JDcMQh sRdNgXGqtNwP0RoryLdLnXmhtK/opCGxDypSHIDHuqpRYXTlf+p7w06Xve7UHo+ShPi3 pqp32baY9jVR+I0efJjtVu+AmgO+3LpuT4UynxSIerl8ymVet3rJ/2kcR1dE9s3PeiNj cNt1o8O0MQyFdMkDpa39w7MDAZBQ8dDP0xwBcN3LYDQ1s0ykX6j3ue5nfJSedi5SUOu9 zovCkzjL+RJhK8EBhqN/PzL4+8vW2Apg2eYaGfN+VeB5CbBmiLCZ6O+XgzMIT8zl8ZES DJcg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1775833853; x=1776438653; h=to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=8AOxuPm95TBFyiaLlqzqvHqB5PlfertzN1d5++9g3zs=; b=PgdClMSVFhHAWf4ZrBMS0Zm4xnCtF4ce3jGwXzvwN6C0QdxlOecGk0/zDIDM63K24x 5OknRoV71qSwk5iAyqKGziSVmQAVcd6AoUFC1Fl/JHG558q6LcN4J8Ctcjg4cgcI/EVF aVAzNElK37tqEF/p37oXDhq8zrz5V5+lZNyjOmwv9odWdk+ttDFGG8Y5myXSNPjDxuRE HQEJ0h0BTv3KINWnZ2aPjb+sjVyWmhVe9LKz5LOfwwoh1YTgLM4JZhsdiSt9ks7bDKZW PjuZxWMlcwdnToD0xNvQXYJkx8CbwBH2n2bAi+I9kOnXpHJyf9i932PpXlz1EK+BvO7f z26A==
X-Gm-Message-State: AOJu0YwukDZa3JeAJcJ4KjAURpiqwz/h9GTFyjp46dkDi/NuHY4/zFec xwiTRLM+SZS8wcWPVfoIYlZEkvl1wGNru9poXlr+yTfRmXq3VZDv8ry/d9U3cVoeqvxmzy//LO4 TXfy6NTRvCf2txa/06c0E1SRFRhvGZc+dBwQY
X-Gm-Gg: AeBDieso40oHwXyi/zgBKRdfS6m4mz72+gtYRg66DbXoEL1iI+mI7+/x/KtTJqs5wU6 GTcfPIvHpZxxXiwJde9ga/DkewsoEUDDxjYrySgcF0oEPVs8fOPaHipupRP64oqWtyfwlKDvrCB bhuXplYXMtNhzlfRrCAt7c8NknWjdgmikn6EPvwljgB8UhCHyEDmSbO6/JNOpLLtZid6xYoEIIx Sn3+Xwg50zWvVkI06A+hV5ns6TKEjnfIdHrfrWn0nyG2+9/cVdC964BpscZze8FfWCSut5MEXvG yIu73QyB+i4Hmo9XkhCg2+kzSn/DRGKb69+suJ9bYPDIQahZ7couTm8nuUYPC5ek/LuExAVl2yc thDwx9Kjp1HePWmOJU76VEoj9y/SQrMvf/k1CV57Y36h/gvU2RILSdW7ddA==
X-Received: by 2002:a05:690e:190d:b0:650:1aa5:8594 with SMTP id 956f58d0204a3-65198bb02fdmr3493774d50.49.1775833853136; Fri, 10 Apr 2026 08:10:53 -0700 (PDT)
MIME-Version: 1.0
From: Soatok Dreamseeker <soatok.dhole@gmail.com>
Date: Fri, 10 Apr 2026 11:10:39 -0400
X-Gm-Features: AQROBzD16LmrTWLLM9hrhFYkLiEh2fyc3wuoKIwMkJkdACS4yxA_j35ujoxlFEA
Message-ID: <CAOvwWh08s5eeLbY_tXFhinJOSzjhDj_rktLvQdkf1=_4U74kyg@mail.gmail.com>
To: mls@ietf.org
Content-Type: multipart/alternative; boundary="000000000000ff1139064f1c891a"
Message-ID-Hash: UR6T3YJVNQKAALDJ5OZYBYK3XPOJULQQ
X-Message-ID-Hash: UR6T3YJVNQKAALDJ5OZYBYK3XPOJULQQ
X-MailFrom: soatok.dhole@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-mls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [MLS] Thoughts on draft-ietf-mls-pq-ciphersuites
List-Id: Messaging Layer Security <mls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/goy5Lzp4Sqht5fUSQTXJuzpR9hU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Owner: <mailto:mls-owner@ietf.org>
List-Post: <mailto:mls@ietf.org>
List-Subscribe: <mailto:mls-join@ietf.org>
List-Unsubscribe: <mailto:mls-leave@ietf.org>
Good afternoon, I'm working on a few projects that intersect with MLS in interesting ways. The most pertinent of which is a key transparency project for the Fediverse which I hope will enable the secure bootstrapping of public keys for use in end-to-end encryption (which should, in turn, use MLS). You can learn about this project here: 1. https://publickey.directory 2. https://soatok.blog/category/technology/open-source/fediverse-e2ee-project/ The actual E2EE on ActivityPub folks (mostly W3C or W3C-affiliated) are coordinating their efforts on GitHub. In January, I opened a discussion recommending specific MLS ciphersuites here: https://github.com/swicg/activitypub-e2ee/issues/59 In recent weeks, Google and Cloudflare have both announced a 2029 timeline to adopt post-quantum cryptography everywhere. After talking with some folks at RWC 2026, and seeing those announcements, I'm planning to update my proposal to migrate to ML-DSA-44 instead of Ed25519 for my key transparency work. Ideally, we'd also be able to use ML-DSA-44 for the ActivityPub E2EE work as well. However, the current draft is incompatible with my goals. Notably: 1. No ChaCha20-Poly1305 ciphersuites 2. ML-DSA-87 is in the current draft, but -44 is not. I specifically need ChaPoly because I am implementing this in languages and runtimes without access to a native cryptography implementations or raw Assembly, and may be running on hardware without hardware-accelerated AES, and I trust myself to implement ChaCha20 and Poly1305 in constant-time, but I am worried about JIT compilers and VM optimizations undermining my attempts to make the AES S-box constant-time. I recall there were some concerns over the ML-KEM-512 parameter set being too close to the security margin for comfort, which motivated the prioritization of ML-KEM-768. A similar concern was not present for ML-DSA, and the -44 parameter set is considered secure with sufficient margin to not invite the same kind of bikeshedding discussions that ML-KEM-512 provoked. For this reason, I do not feel that the -65 or -87 security levels are required for my purposes, and therefore cannot the bandwidth costs for the larger parameter sets. I am ambivalent about hash functions. SHA-256, SHA-384, SHA-512, BLAKE2b, BLAKE3, SHA3-256, SHA3-384, SHA3-512, KangarooTwelve. These are all secure enough for my purposes. Given the widespread availability of SHA2, my default choice will be SHA512 or SHA384 (since they're both fast on 64-bit hardware). I acknowledge that asking for the draft be expanded to include a few additional options risks a combinatorial explosion of combinations, so I will instead ask for one ciphersuite be added to the list that includes both ChaCha20-Poly1305 and ML-DSA-44. That is to say: MLS_X_MLKEM768X25519_CHACHA20POLY1305_SHA384_MLDSA44 Where X is either 128 (conservative) or 192 (which seems more appropriate to me, given that the security of the KEM is >= 192 bits, the AEAD is 256 bits, and the hash function's birthday bound is about 192 bits). Thanks for taking the time to consider my request. Kind regards, Soatok
- [MLS] Thoughts on draft-ietf-mls-pq-ciphersuites Soatok Dreamseeker
- [MLS] Re: Thoughts on draft-ietf-mls-pq-ciphersui… Rohan Mahy
- [MLS] Re: Thoughts on draft-ietf-mls-pq-ciphersui… Soatok Dreamseeker
- [MLS] Re: Thoughts on draft-ietf-mls-pq-ciphersui… Rohan Mahy