Re: [saag] sntrup761x25519-sha512

Martin Thomson <mt@lowentropy.net> Tue, 23 May 2023 15:21 UTC

Return-Path: <mt@lowentropy.net>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 61C3CC151991 for <saag@ietfa.amsl.com>; Tue, 23 May 2023 08:21:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.095
X-Spam-Level:
X-Spam-Status: No, score=-7.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=lowentropy.net header.b="Nhyg6l7W"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="lH8ua9ug"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0hBIJ3s4mjwX for <saag@ietfa.amsl.com>; Tue, 23 May 2023 08:21:49 -0700 (PDT)
Received: from out2-smtp.messagingengine.com (out2-smtp.messagingengine.com [66.111.4.26]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C1569C15198D for <saag@ietf.org>; Tue, 23 May 2023 08:21:49 -0700 (PDT)
Received: from compute6.internal (compute6.nyi.internal [10.202.2.47]) by mailout.nyi.internal (Postfix) with ESMTP id 0E2E95C0214 for <saag@ietf.org>; Tue, 23 May 2023 11:21:49 -0400 (EDT)
Received: from imap41 ([10.202.2.91]) by compute6.internal (MEProxy); Tue, 23 May 2023 11:21:49 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lowentropy.net; h=cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:sender :subject:subject:to:to; s=fm2; t=1684855309; x=1684941709; bh=ha kCNWzVpk8wp2qrbF73kkcH4hAis0vYk/2adDVr1MU=; b=Nhyg6l7WlzDRTvx9zA uiseonag6qkZMczp99nRQO8ld0j4pp+ncYu1JzHyw+w6a97YxxSzVPY/YMwF7Zt4 9LBG44/hez5N1YD7ITqtwG+ZOW/WXBWRYG+7EgZh7HGb/TuLVT6XO53Inyg6sbuC zUl/+/tEGcG7kGmP7jJ+PKfKIO4DDRf0xiDZQ8HgwfwjVCGcl2AuU2RhKroc/dI5 V2AiXOznCJC+vX4LjOWZlahDSkJT+rETld4eS0M1E7fZOdkX+7h1BXIpN28k59T9 nBYSGzDlcpwVrjcdtSgfkgupMtMYThDZJ/ARyDGLVaRBNd9Yq0UQlDe+9+UMbQuy +xdA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; t=1684855309; x=1684941709; bh=hakCNWzVpk8wp 2qrbF73kkcH4hAis0vYk/2adDVr1MU=; b=lH8ua9ugpBX+QeyTw4QSbyTaN4YSS cuLP7DfluQSvGIuOmfEZXLCy1gAbDo1vHymwPNL4Byvq9HJfHexr1CTeK6CeYqvV qKXTWc4xD+rVKm9Si75f4wnd8HwzWQBJjFkY96rh0y1o7Junux01SP2rOWkhlC4n v0wW7eHRyD+spNtnNmF36SVH8/a0EIKXoAXvSgIC56t1P1BX2moqi+CW253nPi6S mdui87NMgBBfFY1qibaajagx39nTuTLbJQR3AR/DajsCO0W7Bc0vXa959lkz/U0K qKqemtNuLHel9msg9l3NintKqEUW65dEaB9XlVdd4ugEX1TVq0oMTNKuA==
X-ME-Sender: <xms:DNpsZDuAeVKm_TRbUZYxYHvXEe6DOZWQ42dbWUgL1xcB7VgTPlpD9w> <xme:DNpsZEe3Su_Bsx3aq8e0u9c7659Pi0tFzK__YPyHqoD74sFaL95cBSVh_XIgGecyW V0PmgyUQpNC9zM_2vY>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrfeejfedgkeegucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpefofgggkfgjfhffhffvufgtsehttd ertderredtnecuhfhrohhmpedfofgrrhhtihhnucfvhhhomhhsohhnfdcuoehmtheslhho figvnhhtrhhophihrdhnvghtqeenucggtffrrghtthgvrhhnpeekteeuieektdekleefke evhfekffevvdevgfekgfeluefgvdejjeegffeigedtjeenucevlhhushhtvghrufhiiigv pedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpehmtheslhhofigvnhhtrhhophihrdhnvg ht
X-ME-Proxy: <xmx:DNpsZGwrToKgS8rxGnbxTTbKNti3lxsMoy85SXNq3MyQYXIVzPPxIQ> <xmx:DNpsZCPxvqpEbGm97lqJrgTuTJJllfJ7s015V-8CSsBLCALyiU_xeQ> <xmx:DNpsZD_ieSIb-SqqsdbwmtnguWhxZrNBlRqO6tVqFXdur1mL9aAo0w> <xmx:DdpsZGKXJdKTStU8fdVL_Ft9vaAkTx488uwfIp8ygwQ11cIXwr7dlw>
Feedback-ID: ic129442d:Fastmail
Received: by mailuser.nyi.internal (Postfix, from userid 501) id B7BD1234007B; Tue, 23 May 2023 11:21:48 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.9.0-alpha0-441-ga3ab13cd6d-fm-20230517.001-ga3ab13cd
Mime-Version: 1.0
Message-Id: <b82f1264-3935-4ca0-918a-fdb7f819c2bf@app.fastmail.com>
In-Reply-To: <87fs7nxj9f.fsf@kaka.sjd.se>
References: <875y8y4ip2.fsf@kaka.sjd.se> <84296E62-5843-4E7A-BD43-430491A5A1F3@akamai.com> <874jo8ytgw.fsf@kaka.sjd.se> <f6aa133635084609b0032ab1cfbfb7ce@amazon.com> <87sfbny046.fsf@kaka.sjd.se> <CABcZeBME4CRjd+4kqFCzYOmaOEafUiabsBoUQ0Eqm8A7OD-46A@mail.gmail.com> <87fs7nxj9f.fsf@kaka.sjd.se>
Date: Tue, 23 May 2023 17:21:26 +0200
From: Martin Thomson <mt@lowentropy.net>
To: saag@ietf.org
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/1Hpm_nvUb-JPhlmTMfdNHEGR_mw>
Subject: Re: [saag] sntrup761x25519-sha512
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 May 2023 15:21:55 -0000

On Tue, May 23, 2023, at 15:35, Simon Josefsson wrote:
> In the same way that if the IETF decided to change the details of a
> deployed protocol, then the implementor community would change over to
> that code point, yes.

So if the IETF decided that Kyber was preferred to SNTRU (as Panos suggested), that goes too, right?  That's a pretty significant change, but a good test of whether this is IETF vs. independent for me.

I think that you said that you wouldn't be interested in that outcome, which is why I suggested that independent submissions would be better.