[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

Yaakov Stein <ystein@allot.com> Mon, 29 June 2026 14:28 UTC

Return-Path: <ystein@allot.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 0FAA7109DA3EE; Mon, 29 Jun 2026 07:28:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782743317; bh=fGzehbBXFCMSB1eFa6j9s5mw1H5bfb6O2MsBqbcq+Bk=; h=From:To:Subject:Date:References:In-Reply-To; b=vNfaky0vzIPLS6LV5a366MraiuQhDuqDyBC2f5xAcKL8BSkXFduGVaeEnB+Bz85mm iONdQ262frzmDYCm4sKFt3JbMnAqaoAbdnQjr7QbAV4EFvRUL8YJ9HjGFmtAU54yRi CW9udUxUIx2PgI+U0/WpsrVQmmH9zVnIvvpF5VDI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=allot.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qUfwSIpEAPSQ; Mon, 29 Jun 2026 07:28:36 -0700 (PDT)
Received: from MRWPR03CU001.outbound.protection.outlook.com (mail-francesouthazon11021120.outbound.protection.outlook.com [40.107.130.120]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 548EC109DA3E5; Mon, 29 Jun 2026 07:28:36 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=wdySdZOkxLQB/5QR85HnsGE14l8cQrmjP0g3iSf9MZ79/guHni4EaSfuWR4XWNVa+0d/1H9LUQkNVnbkA1gYHDtPus/526gvXANnCuxonHRLw2nNk3ukLuzQOknhU/vkAZ8KH/ZH/j1AH+nIS+yj4i1/ND/fikdUVUpWQxKYFD94Ud3ilx1b7j6Ia/wgSRFTEhSRXNWKZ+LIjuSYL9OLBS5iBMJZni/ZbwFw5QiIz3pNyBfw2pxlWZjQuux9XdQPIDlKw2Wxvm7CgYt27UDT04koEW/QinrN8UOOj9q7qLDuAlnZvMUhbaYjHdnWg/LnoF+yk+SLKr94wKMYmpZA3w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=fGzehbBXFCMSB1eFa6j9s5mw1H5bfb6O2MsBqbcq+Bk=; b=DqrcTmOX69Ch/lU4SXPBacToChDAx4plV8njoAlKS4h7TyeVKy78JjJtPc8Wi1Of3+fGhX8qbOUst05RGEoF8/aHQglT2RdPAvCs+jvSpZx8RRa3zWd4HbQAiUiHAxCbEZr2TbbOc76Xiqk8n6+bw8QCF6UKB2GrYRLNI4R2eBj4hT7MSxxNQihDLB/5p+lphKnJGlfYpgxVhhcjgYOFVO2PxUB1OfQ3Nu2PnH9Yi2FBjS1JzoBTauG8xSQgcCcJ9hqEOJbOvROKOo8oqc+Qq8hLgrxb2eL7w+XUa/aUcKGrbm4HJQeGmj4ezAjJlvj/FAQPVqLcHpVSnXjBB06ZaA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=allot.com; dmarc=pass action=none header.from=allot.com; dkim=pass header.d=allot.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=allot.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=fGzehbBXFCMSB1eFa6j9s5mw1H5bfb6O2MsBqbcq+Bk=; b=kZui/cG+5c9M63jNote2PNav3ZVohfawAcYfT1rK+7ACEypT/VBpOimZaryWFoqm+8ywVtfsiNbo8b7NhE5Gv3rFrvDuXjsOqf5wiQ70D6L3joe3tMqItMv7qouO0Jlmrn276DxdHbG3EV87BZhErki/ovEPwVhVTled8NEqMDw=
Received: from GV1PR08MB7346.eurprd08.prod.outlook.com (2603:10a6:150:21::6) by AS4PR08MB8191.eurprd08.prod.outlook.com (2603:10a6:20b:58e::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.159.19; Mon, 29 Jun 2026 14:28:23 +0000
Received: from GV1PR08MB7346.eurprd08.prod.outlook.com ([fe80::c681:b002:49:d763]) by GV1PR08MB7346.eurprd08.prod.outlook.com ([fe80::c681:b002:49:d763%3]) with mapi id 15.21.0159.018; Mon, 29 Jun 2026 14:28:23 +0000
From: Yaakov Stein <ystein@allot.com>
To: Antony Vennard <antony=40vennard.ch@dmarc.ietf.org>, Joseph Salowey <joe@salowey.net>, "draft-ietf-tls-mlkem@ietf.org" <draft-ietf-tls-mlkem@ietf.org>, "tls-chairs@ietf.org" <tls-chairs@ietf.org>, "tls@ietf.org" <tls@ietf.org>
Thread-Topic: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
Thread-Index: AQHdB9OKlTCr8xaLBkex/7fcmM9YZA==
Date: Mon, 29 Jun 2026 14:28:22 +0000
Message-ID: <GV1PR08MB7346E945D86A9555C78920C5D3E82@GV1PR08MB7346.eurprd08.prod.outlook.com>
References: <178231320760.1520243.5914961961176039994@dt-datatracker-f9b87776f-8pmmg> <2366159b6976368114c8c036bf379fa3e5795a6c.camel@vennard.ch>
In-Reply-To: <2366159b6976368114c8c036bf379fa3e5795a6c.camel@vennard.ch>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=allot.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GV1PR08MB7346:EE_|AS4PR08MB8191:EE_
x-ms-office365-filtering-correlation-id: 6a086cbf-286e-4eb1-a2b0-08ded5eaacb4
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|1800799024|10070799003|366016|23010399003|3023799007|11063799006|4143699003|22082099003|18002099003|56012099006|38070700021;
x-microsoft-antispam-message-info: +fWpkwk9pWMQLABi3C2EbEcFdhfpxe49Iyzq2gfQtdPDXhFqcYbClWtZYZ52B184WNKBvkEgjo6/hsNTUodFcJbW09VcaEfWn/XvPsrAM7txtw6wHQz/VlxhKMlGe2BjbU4oG1GO+Jc60TLGqLO17D59lfaFHcu/pos/Gfvx0t8mX+3OPEV0+2XEKqP5xpW8cnNlQzcb14M92kfgXyDOjmQuBGvF+y1gnFuifNkkQGz0pI/ByGRd4QLxgtzmeyaaMTCyCTGbHz/l4WiJPDX7kQehGzrej9agAIGLO5/Gk0wqpvrelJd4iz8iPM6tERXJmuP9xdkadVnb+SqbgT4YZyWg1xFhoqb8eQtSbvxSDS/MBHF70Mq4ZBdVLneusQ3w9pJqM+/YoNMGz64SgIwDfi635JAJNvqI+Y9/lZ8ignvdolyU6q5RQlURlMe7u4QheLLT9vK1QItOtz17u10jDFvmVVGVf6IDk/W+e8NOpL5MfavnVN4qSjcNtrZ+Rn6jFhx9EIZYFnM5F30KVrU4sW2/DkGtaeJ2Csc8eOGJMv7QwJ6myc7GbXy3uBEmJoR8C+NHhc/MfI2PYo1IqDEA/Z2qgT77Jv6GYjS1uIewfjG7Jnn40zASk9XN7y9Jb5Ub9qw6AvfeWKqjo5LAir76La5rVyl1OOqFEeuy9O0TMRslg1Odc52tu4buuACM+C1qVe971egkWRJAmhUMshgz5A==
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:GV1PR08MB7346.eurprd08.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(1800799024)(10070799003)(366016)(23010399003)(3023799007)(11063799006)(4143699003)(22082099003)(18002099003)(56012099006)(38070700021);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: mgkogb/Oq7AlWWzEmVINipDyPqSLbr51Xo8Ay9yZxhPqL1YeXXaskuGOw4Eq2yCSH1nTPtKff3jQHw40O5g2SBe7CF2bn9UT7Qzf0OV4ZagUBa7zTsFlOS4tEdzYcjq2HqXoCiZPVSofZPWB5kYeGTpNUNyBzqsR+Q3+n5RsylAkqKTvVfsrqF3G/BP/Os6RoQXIr40yMsTcsVgekMe4yOLqPFa+AFvZkPKTYpOR1Krznr9EiMFgmmc8JrQ02e2n67jdWcJcMPcRxpTVkXokRF9mTpKNOQdb8WFAqwOqhcZbn7vQUMf8EVdx07f56NT+suOHP/EtqPcinNbHhaYymJ+HPFjhsvyvlG26YikChOsi06gPBlqd11gPa6At9CryMXdgOjLqkqSNgvww22tUEVWtGQI+6lXAo491i4jKxcmJacxOkTNtZrPlrGoZmmTFm+9Z3EjvW3l4GwP1B0wxGoJEnPGB4NqyQyl/OHCZsoWoQvRypQAGlpUuaCt2pfSmbI3FXIaReddNQMvH2pwAOdBxD0z5HtCVyWH+KlBXksqJzjEk78lZqQA6yu2cckPyMfxYEZ9FDoDiMO6oDpjdLpecXNl4mhhpfLmjT1SOCqwAkQo1lnSxVdK3OnqUGyB16+f0bQxIC/MYF4MsiONWlYVXjr/zWNCZfdUmgYo+5TGz5IhItyFouTWgU8rdm+QhnROMBJLcZ1jYXfP2DfAKFmlNnfcfl2tnXUkqgh7ITtu2mlRC7cQQeH8Pavz+CwLTO8ATxw1qupu4naN10MgiXEd3mRLoHxb3HMyVbul18m7cp98PfEmxpUPqSeQHW3d7rxd7UTet8w9Hss4Qx4prQovAKHdihOTnunD4BLz5p2n8U5GI+ncrprGZyeFrb2e6aQovVqIz+6urHi0Xg2VVk1PQQUjf+y+PSxCi5leQ9Y024DnzRM29KIp4jbXbVFNtxcxZXaYycpkKNZquvv3EAdjWq+dcqqMvseB0RZ+uMFZw+IrtrEmCnIgHVXkYFXFrgoL7CtOPFTvndMLmS8km2Yfl4F+mSdgZZ6KhulggUcFN9Zb8RehpmiwCZR2EvjBZkHKH5TOHCSiMor8zKTOyMUQMFdhW6yHpjOYcHR39EtnbmuI8hTEMO+mBW3oUtUsSTlkIjJQiYKgrTSZfKpD5JdszkoamBoOdeIHGHfjHmjeFdLaWj7k1oFer1pjw3EIv1fcw+XCAVQ2hV/TH49CdQRKj0useCb3KcFph2kose8aOGzczCLDVqPhuzY8yHUw1qQQuC+hl6hpI5gOxTqXjqwmdErNL+ucL1yeJ3c52CZ5s20k0+mHhz0+ij4OjMdHiufALTOmb1EtURD0YnWTmFhtMKT9mhWksW89worZy5YRqeZ7J48ANQBCsUJIFsbuoFrNykwnqP/Lu9AcFzfvoJKTzby0eUPl7YMAjRpgHmNQwwqsbin6glnHmVeGoTQ07UEyinJJO7jrsP3nW2bgzOZVYdSKKfoIKbWIX6+dgza8j3NCdpJxnpJQu3httpKHu+QDMbnXU5hN9ZKBivpdHQgY4EKSDngeHChieUm4xqnTgrcnxC1DePZYqeS97hIZoeoLIExNaxt98IxAnJj5dR7Lxsjc6Zxkv7FX6j0gOTUYlfCnn+wPHL3Hgzp9jGOxlabWWPgEI7nYAPVbrXfQ0ZOYu7tKjmDOLrGg4N7/n3P8a/GngnYFaOTelh+ZAO8zv91ES+cb9Uola75ZyaXv7z7Hjw/Hk/z1z9Ju0BpFmJy1SgWkjhieNhUUnwbl3uUoY
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: allot.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GV1PR08MB7346.eurprd08.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 6a086cbf-286e-4eb1-a2b0-08ded5eaacb4
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Jun 2026 14:28:22.8690 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 789e5ff8-0396-414e-803b-13a424e9f5d2
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: eCbOuuOil7d3tUk7Nkj4iaVL3DG7DSQr2sQBxtOObMjYuqgaegpESjS4ao9Wc13xw99Tkxo0N1KetwH8ga4dug==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4PR08MB8191
Message-ID-Hash: 2N6Q55I4CRRYJJ5LHV7LVWBRRSBM3QRQ
X-Message-ID-Hash: 2N6Q55I4CRRYJJ5LHV7LVWBRRSBM3QRQ
X-MailFrom: ystein@allot.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/5Ow38mh6RLymbuqfrPtrKRnJUXg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

> That said, I do not believe the risk of ML-KEM (and ML-DSA) to be severe:
> there is no known cryptanalysis currently exploiting rank >=2 module structure at these parameters that performs better than generic lattice reduction.
> Module-LWE also has a (granted, an asymptotic) worst-case-to-average-case reduction - something neither RSA nor ECDLP had.

At last, a reasoned argument for believing Kyber is strong.  In fact two arguments.
However ...

1. First argument (in my own words): “Module‑LWE has more structure than LWE but less than Ring‑LWE,
     and no attack exploiting this residual structure has been demonstrated that is any better than using LLL on SVP ignoring structure."

That is a good argument, but the crux is "no attack has been demosntrated" is not the same as "no attack will be found"
and certainly not the same as "no attack exists".
Modular LWE (k>1) is a compromise between efficient but insecure Ring based (k=1) LWE, and complex but more secure LWE over the integers.
We can't yet be sure that this compromise is as secure as it seems.

2. Second argument (n my words): "Even if I can break an average case RSA or ECDLP (e.g., using a CRQC)
    there might be worst cases that I can't break (e.g., Shor keeps trying over and over).
    But for LWE, solving an average case reduces to solving any general (including worst case) SVP problem."

This is a more interesting argument. However ...
Who cares if there are very special worst cases for RSA/ECDLP unless we have ways of finding them and using only them?

and

I assume your argument for LWE goes like this:
        breaking ML-KEM   implies   solving general module LWE   implies   solving worst‑case SIVP problems
I don't really buy the first part, because it is bad even if I can only break 90% of the ML-KEM instances, but I'll let that go.

The second part seems to follow from constructing a noisy representation of a SIVP problem, solving it, and then returning to the original problem.
But there are some assumptions here, including the asymptotic one you mention, the vector to modular transformation,
but also (once again) who said I need to solve worst cases? If I can break average modular LWE that is still a major threat.
And, of course, we shouldn’t neglect an undiscovered structural weakness in the particular ML-KEM methods
(several problems were uncovered during the NIST rounds and fixed, but can we be sure all attack avenues were found?).

Maybe all of this is stupid and it will all turn out perfectly secure.
I truly hope that this is the case.

All I am saying is that if there is a cheap second lock that protects us until we can be sure,
then why not use it?????

Y(J)S


This message is intended only for the designated recipient(s). It may contain confidential or proprietary information. If you are not the designated recipient, you may not review, copy or distribute this message. If you have mistakenly received this message, please notify the sender by a reply e-mail and delete this message. Thank you.