[TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa

Watson Ladd <watsonbladd@gmail.com> Wed, 27 May 2026 21:24 UTC

Return-Path: <watsonbladd@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 50646F63CE34 for <tls@mail2.ietf.org>; Wed, 27 May 2026 14:24:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779917063; bh=KZkX8QQ0KHSrtClcF2kZX8gAbGKvYqHsi69etHIjr0A=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=DCqmiJs21kAkcljcodJo+Rhu0vgJEsSWZomXM+Yj47BY+0Y7/76IETDv3GQdj/Mnb IAROhNrKfE/8bYGB3e6hN+frua+E+mReHJrVOGZHVMeTyI+cBmQj9VHDIrmzKw/Ydv 04GI6YhOiiofQmDCKJKVlO5drAnvcR7ys7yeOF0M=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.099
X-Spam-Level:
X-Spam-Status: No, score=-1.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id A2Lw7uiJ8tIV for <tls@mail2.ietf.org>; Wed, 27 May 2026 14:24:23 -0700 (PDT)
Received: from mail-wr1-x42c.google.com (mail-wr1-x42c.google.com [IPv6:2a00:1450:4864:20::42c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 15A78F63CE2E for <tls@ietf.org>; Wed, 27 May 2026 14:24:23 -0700 (PDT)
Received: by mail-wr1-x42c.google.com with SMTP id ffacd0b85a97d-45ed9336049so1811903f8f.0 for <tls@ietf.org>; Wed, 27 May 2026 14:24:23 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1779917056; cv=none; d=google.com; s=arc-20240605; b=gGSTmY5oFmwZpDw9VKEttj7Eh/sFU5H3I7x0+mQhSdCVxUZP8uAaUJn4xVswtZk5nl 3a3Lgq5Zo0E0F00Ot135xcEQlFEESdcgGgzblVATXKb/hPeS5WRkIlgpWapZAcHGkeg9 aHYsOD3P8qTpUzTGEzRpzZmTAjZDn5xOKjmf2CGzvHzAPfC8Ji7AhhI1zH9oGB/sP8CT e2/rPzpTRlDA5B5wA2qTNDC2VZewa1ZW2MVpMZW9dOtd0ChwAALp/2OHKRticM5+hi5e pEK4WRW64c74E+Q/8nYuAtSfEJdp7qMuFbblIdJov33ylR1ujiUgxJoYRw1jHKQ3Cf5a 2nSA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=o78yFCXgXvt60hNmasettdXp3BvLLobmmPM/TQp6rM4=; fh=m8GODr1AvyrmJ26YY/Vi4hidOvGHZFcy/L58n2snyto=; b=kCjhxLEvHmjkr6RvB1ZopL5a1+4IoTN7OZGKIwI7acpnjtD6mpIHWjgNWs5KQhM1yO jBOS4t36tDf5GmHU3ZyWGwZjXFxQiLH4tjhWt0Rkgte2uruuae8nzlMUWTZiSEb4OWSg YAwacnTRAkvkxaHxBr71FVso6oU/55sp+fEO0tppTqPwA51vMk9p17QCBP7vAde+nCso JDXgYKKsU/XDSz306k7jfx2SzDuH6dMaV3BAPD5hpKY7RjjFRE4sfI713p7YdmXmm9Zw aU7MeZzW+QJCge6iC4+FBjTsiRi1MKHDjBggxyB12jMBuhWh3aHv7x8BygLbau52wS4u 18hA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779917056; x=1780521856; darn=ietf.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=o78yFCXgXvt60hNmasettdXp3BvLLobmmPM/TQp6rM4=; b=QrY5LYPKrpn7uNVC+Xtfkxf628vKeo2A9t6xoPRz9H2bEaSWBR/l+snFLvaRIDoJP+ 4R1s52NAuPWVO3NQhipiq4mzRheAUVqKaad3O310hgksFrU2D1PGj7VztgAqqMhbNhk/ Yw/usnTPIOtoa4qdP/NRxfqnmCWXQxWhEDEjeKpb+ADJV2bJUSN13ol4SD+eN04DpF4y US64/MvzweYy7obKRjj7MVHKrMF5IkUL7S8rIzocDy3Xt+WpixBavB9aTiu8Hu57PdpV hNUocjeiRIkZYc/TOnlTjAmITAhxVhpY47bmPkTLUuDTUaNBxiDtYJOMVfhIM92YjDeb LpMA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779917056; x=1780521856; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=o78yFCXgXvt60hNmasettdXp3BvLLobmmPM/TQp6rM4=; b=kF5djTMQLTkbKP1S3qx3RZWZ0eC2vil3+Nwsvxe4vAVfJdsKZQROMg0E4X1sEArJlr pODbdNkaeM+TEySjCs5O4CXf1kQxoiFs3ln9IaxYx5JAudmVJsPMj9N/vIGqh9SJ3jOM 0engmRmETm8XkDtwI9Hy7tCf/1PMOO3Mlm3rB0NH4+8IAlXFMqR2ZP5xSnIfwfxzdhp0 Rx5VSkIMdCzWTcGB9R/p0xb9oMA76zxWR8w61FlA9eOTD0Od+zohQkYKcTVdzUbBRfWN SwdyhZYmORvX554DovZ9wTwCnTksmkFZoF6Lqg5NIu+GhKxjRSdAye5vnpdTU1ITv+01 ozoQ==
X-Forwarded-Encrypted: i=1; AFNElJ9H6pW7FynuWOhf52KNpZVTSjmw/mZrb3JJGR3zLnwV8suFM6UkTdRCXRxblMRbRwgd2iE=@ietf.org
X-Gm-Message-State: AOJu0YxstvS0lfIPipnt4sXRkmrjfKEGYzy1PSPfp7yAsi2WwVLTpU5d PXp8LIE8pZIe3pempq9AqIPW//rsijviteglZdIHjg5eWXlpt6Wo7FhD5qDUWQTRwv3VPGQNTnj s//LM8zBonjpFTdB3cKhNPnVDqHc+1Qk=
X-Gm-Gg: Acq92OHKHydT8E2COF7hzvDe8/zM41pFmEYLn4sobl/QvgXDlOk6B1uK/OSSYjycdvA BXf0WfZsaAE+V962m46VP5IZjga3WLqJNjVTbipIrh4cjKQqOc0evr+5/uxtG9mWUwLEFpEMixI WfkKPLlYCeTxJ/Gd9qhzz8BuEIfWiWZRi1z9ML5fH7NCPhDrnmOh4EqGRmpkG9oeIkQDAvKikwH zBeheV5Md0ShpNmtCZqT1P8WW1ywxGjGlLB1c4S/CuE4BoIWE2D1G8jTb9aXg2ZhE/krk1khjww ewWsi4qyOV2A2dN4lTPgI8ZKpyCKsG44fQNaJaQ5qX1iNkz7XHus6BWY/+nwi+QINWeLm7AiMYN NxYqdcWb+3AeFdyKreE41yOtaobBsT1UHzjCWbCCOu5BicE+vqFlbGTdSfEw/lD/UXM03
X-Received: by 2002:a5d:6f08:0:b0:43d:7c1b:b8c7 with SMTP id ffacd0b85a97d-45eb36ac4cfmr38085589f8f.21.1779917055995; Wed, 27 May 2026 14:24:15 -0700 (PDT)
MIME-Version: 1.0
References: <20260519112813.1254795.qmail@cr.yp.to> <CAGgd1Ocy8f4HeQy-qWauAJAxizznXdXA53kWVp_FV1QUVGuxWw@mail.gmail.com> <5DFBF81F-4A98-4C5E-A060-580DC6960021@symbolic.software> <87v7c8lgt8.fsf@josefsson.org> <CACsn0cmaOdG4vCdeOVSxAPnJtPRH8rBJ3sfAY3o0f1fm-ouceg@mail.gmail.com> <ahddRzOIvQDXcvaG@ubby> <CACsn0cnStbBw8Szq+McPumjExnbL=3wmwESYEMWczJJZbJXRgw@mail.gmail.com> <ahdflj/Xy8VoOfH5@ubby>
In-Reply-To: <ahdflj/Xy8VoOfH5@ubby>
From: Watson Ladd <watsonbladd@gmail.com>
Date: Wed, 27 May 2026 14:24:01 -0700
X-Gm-Features: AVHnY4LP8iQVKJBHCCRgv4tQ3jrGBrHQYIv5r_05nmmpSLSbo0_uH5XiK93RdAo
Message-ID: <CACsn0cka8J0rkBENoNAMhS_RXJB2eHogwecZ7KvaB+UdFPxRiw@mail.gmail.com>
To: Nico Williams <nico@cryptonector.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: C3AKFWCUQLWBJAFGLVRKHSDRH2FFATI4
X-Message-ID-Hash: C3AKFWCUQLWBJAFGLVRKHSDRH2FFATI4
X-MailFrom: watsonbladd@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Simon Josefsson <simon=40josefsson.org@dmarc.ietf.org>, Nadim Kobeissi <nadim@symbolic.software>, TLS List <tls@ietf.org>, "D. J. Bernstein" <djb@cr.yp.to>, stndrds-inacio@andrew.cmu.edu, "<iesg@ietf.org>" <iesg@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/79AFZJZ99-kiHgCkMjgO3uu2I5g>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On Wed, May 27, 2026 at 2:18 PM Nico Williams <nico@cryptonector.com> wrote:
>
> On Wed, May 27, 2026 at 02:11:16PM -0700, Watson Ladd wrote:
> > On Wed, May 27, 2026 at 2:08 PM Nico Williams <nico@cryptonector.com> wrote:
> > >
> > > On Wed, May 27, 2026 at 02:01:08PM -0700, Watson Ladd wrote:
> > > > On Wed, May 27, 2026, 1:48 PM Simon Josefsson <simon=
> > > > 40josefsson.org@dmarc.ietf.org> wrote:
> > > > > Repeating that statement doesn't make it true.  The analog motivation
> > > > > for doing PQ hybrids is Man-In-The-Middle attacks.  If your non-hybrid
> > > > > PQ signature has a weakness (e.g., implementation bug), it facilitate
> > > > > man-in-the-middle's.
> > > > >
> > > >
> > > > The only way to achieve that is to have a quantum computer at the time of
> > > > attack
> > >
> > > Not so.  Find the victim's classical public key (they'll gladly tell you
> > > it), use a quantum computer to break it off-line and recover the private
> > > key, then use the private key at will to impersonate the victim, then
> > > its counterparties become victims too.
> >
> > Correct: you have to have a quantum computer *before* mounting the attack.
> >
> > Or to put another way, todays connections are not compromised by
> > tomorrows computers.
>
> Sure, but today's _credentials_ -if they are still in use 'tomorrow'-
> will be.  Who wants to suddenly have to hurry up and deploy new code and
> change keys all at once on PQ day?  Worse: who wants to be dependent on
> their counterparties to have to do that on PQ day?

First off there is a signature scheme guaranteed to be secure if any
signature scheme is. Why not use it for long lived credentials?

Secondly credentials need to have limited lifetime due to compromise
risks already. I have to rotate my SSH key with my employer every 90
days or so.

>
> But at the same time the same pure-PQC vs. hybrid concerns arise.
> Therefore if we thinkg HNDL justifies hybrid KEMs now then surely MITM
> justifies hybrid signature algorithms now as well.
>
> Nico
> --



-- 
Astra mortemque praestare gradatim