[TLS] Re: Discussion about the Deployment Decision
Sophie Schmieg <sschmieg@google.com> Fri, 31 July 2026 17:42 UTC
Return-Path: <sschmieg@google.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A9A35121C8F93 for <tls@mail2.ietf.org>; Fri, 31 Jul 2026 10:42:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785519777; bh=xe8tv39sACFMhQ2UBrTyj69mGiAPc2e8VQp1v/nKaqQ=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=D80SrkEyN4ZA2WkT0OIJaIonCa9hy78uFN98tZoZIexrgEVvsWDYSjvp6dzmmID/Q eCRqrfcMUBoY9Trb5cDulq//r8H22ufWiaN+6bICjsnVRC74uTu84WzgnJm9tahAsE NapSEREJ8ZC+0tCJTwZKpKD19Rj3nR8G1GQ27jXo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -17.6
X-Spam-Level:
X-Spam-Status: No, score=-17.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Yvetk2qu84Nd for <tls@mail2.ietf.org>; Fri, 31 Jul 2026 10:42:57 -0700 (PDT)
Received: from mail-ed1-x532.google.com (mail-ed1-x532.google.com [IPv6:2a00:1450:4864:20::532]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id E76DD121C8F86 for <tls@ietf.org>; Fri, 31 Jul 2026 10:42:56 -0700 (PDT)
Received: by mail-ed1-x532.google.com with SMTP id 4fb4d7f45d1cf-698411099d6so1094a12.0 for <tls@ietf.org>; Fri, 31 Jul 2026 10:42:56 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785519776; cv=none; d=google.com; s=arc-20260327; b=MY6uhlRxftjEPrcbPy/PsGnx/9v0IujmMGMz1N6OrVUNBKFsEpqBTkqCepEn92pk8K kHnZ225PIgxCFZjUbC8WWqhipxJYnK/ulvNkkyQwbQFunmfASOxhcreQKQlQZ35nwbGG g0MvwubVNFpNCEJpoE4Vf+ciP1BfYHoCIxApZI5XaMrKhDoIx+KjKRkVpdLrd4EYCyGH y8H2FA0siRkxEnF4gYilwYMpeYxN3Sv2GNkluqmwo5ZLlOF1wvF4CD+fRFe/gojjPNCT l9Cxfn1sD4iOajZqZDwOcINBtGUOU6gPI4rEdJsrTNsT0cR5xp6SICcRjY0vu8G+CWSI +uig==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=2BuMyeIBMq1PotfAN3oDvDS/urhvi/yYUUNNauQsV/E=; fh=N7S9OWv+au3pREH1rGTrYfufUnNcV3+GR5EeQEhducc=; b=ec9j1qs+MRCP4ZndbL5f1aYuIM8i67UclhteOuxFly0sIabhSQ2CzFXD2k9Sa/NO8B nT//9ijFwnL6XO6PyFyyBYhIxeKDMs6e1anMK+Cb52WGqujxi0d3JB2D4A9I2Xl7FBxh Bzfk83NKFjN0+maH9H2BySWs6hkdQMPlcHofhihOLvnUo4pmyJOQjtkCLrHbH4g02c02 SwNJkE5bZT8tzezQYlwEdug2qkYDN/v7DkemzQLm6SZHvIfHFkdDx5fDuvsBGopFJlQf +9iIEmWQi6IJ4g8JJ21WNhdIu7WN8U4EcT40n/E5gjdHtvh/GCbcSAI0reYX2aAPF+zH D3nw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1785519776; x=1786124576; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=2BuMyeIBMq1PotfAN3oDvDS/urhvi/yYUUNNauQsV/E=; b=EziwPzLCbquqlHWnpbWx+mU/4zKx3bbLI8qTfojUzaxZC+DW9TqYL+acYlOKwzbMTE V8mTrJBhlB59kaVn1/C8Pyv4hTlH1FHYHGRQaPJNfrrPKn10EpmB4gmE2VSjZZTLzW86 1eFkNyg7r6DPth/1Pj2lRTUk1f4O9AGY6qNT68Zn3JPGc4JotaP8TEjw3qs0ENSElyDp ElTqHTGrk/2BTjs7HBGJWaQ3/F3wyGXD/9DzUroQmGaR8vfIWLuvpi7830uE6z9In25m GOzdTGe4mitIKZpOQyENr4I+HOAM6DhM9vc0ExAx+R4Gmht+6QsuJvaiAPVB56a8Y6UR wE+A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785519776; x=1786124576; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=2BuMyeIBMq1PotfAN3oDvDS/urhvi/yYUUNNauQsV/E=; b=NSnwXh8M+eUvstgniV2Gmk6Kz1/TZpGIZj1kxcN+wPt3/wFOl9Qo28wjsqIP2zhmw4 KgygC6pI7mm3kr0/DL+iNxl9lMeNR+n3m4LjbxWSe/4h362DeBFdYmxmzlGHfmJJEhOk Vx3jhPH0k8QscbuSOTaVnEjaoIox5CZiqNedIOHwhxI29Kt1G1JyuVNHbWxsoMQFO7VD CexGvYkh5fxkklruO16gH31brDX5esnoN0jGtn4Pqnt/PtdlZy2yTthyCoKr7DHY2emh ckpqVqYA7M4m4l3SlFsDYnLpscXJgRv+Bh3g+ZX9kdq6/KdvCCfHVjzeLP2R0RD2PkI8 tI4w==
X-Gm-Message-State: AOJu0YzxIdpdRiNMMvfsbx2JXLMDIBKj1MY+5eviRNKgspQ+jeAoMQHS ta8FbFQ3ScsMLquuuyZqdappIpBlZAsT3CYl+ZtoSOHLaZQ08XxSPuxGiiOvc+5WghKDCHLsf6S O5DK0iJ3JauTEWG3Ue6VdQ14VSrMrpAVcar6vifT6bYeF8j6KCK2XRjan
X-Gm-Gg: AR+sD10QGbGX+So9cXWb5Zu4aWg1JRY04a2eD8URUMzL1p59JVU+/S5fJJKucYZBY0y F0pXzK6tvYECu6NNHvgiT9SB/4e1qTkdp9ICvKbrDDJIGezr5I9TVM0yAyL1Y+CkN6mgdaUqtLt 1I2+ps+WYmadHtd2St25MWG2Pp9MTpp9fIksFjPcSdOXNjm1xiG+jgTKDfASt4ww0Tac0Ufapt3 m6rha3VO2TPQT5MhdmK1V80JnFokLF6KxYpywYEh0HMU7t0qs38DX6ynhNQydNs24DmnubMrz68 VdVi0x5oDsGH83SR+iaJrcLD0zHHfUolHxDM0ba5o6a9RcfAmQDhVBaRfKmC6aDt0V5qJ8xYlnw 0unI/GuNoe4/UeUUEkOIljPBPUbbCu9fO4GU=
X-Received: by 2002:aa7:d444:0:b0:697:7f69:48e3 with SMTP id 4fb4d7f45d1cf-6a0a8514015mr7483a12.10.1785519774978; Fri, 31 Jul 2026 10:42:54 -0700 (PDT)
MIME-Version: 1.0
References: <CAEzBKQ4toMtAQ8-d7qK+90dY6b_cr+2v3+YPJXvT5tphRHzxjw@mail.gmail.com> <CAEzBKQ5rnqXEP5ME60ymDOib+wBqyypxppXKXzcMe84gDiJGEA@mail.gmail.com>
In-Reply-To: <CAEzBKQ5rnqXEP5ME60ymDOib+wBqyypxppXKXzcMe84gDiJGEA@mail.gmail.com>
From: Sophie Schmieg <sschmieg@google.com>
Date: Fri, 31 Jul 2026 10:42:43 -0700
X-Gm-Features: AUfX_mzKTMzimIi-rEXQOPUzocfQs_Xdv6C3X-1Aj8BkhaQqqkJZssy9Ft3oov4
Message-ID: <CAEEbLAb4bExRixbxUy=ewLh9yKXc-v9uddtkS6i_D2c16v+Uzw@mail.gmail.com>
To: Paul Romer <romerp=40bc.edu@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="000000000000eeb8040657ebb7da"
Message-ID-Hash: DNPCQYYDL7WEXVRYZXTSZIILPKNI426E
X-Message-ID-Hash: DNPCQYYDL7WEXVRYZXTSZIILPKNI426E
X-MailFrom: sschmieg@google.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Discussion about the Deployment Decision
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/DCxOfKj8kgofeoGLHNM70J09u9k>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
I think it's overall probably prudent to not assume implementers have a degree or even interest in economy. A recommendation flag should do nicely to convey expected utility. On Fri, Jul 31, 2026 at 10:24 AM Paul Romer <romerp=40bc.edu@dmarc.ietf.org> wrote: > log( ) is concave. I should have written "concave utility function" > instead of "convex utility function." I tripped over the change of > sign associated with the use of a utility function instead of a loss > function. > > On Fri, Jul 31, 2026 at 12:53 PM Paul Romer <romerp@bc.edu> wrote: > > > > The response to my message with the subject "Improving the Quality > > ..." has split into two different discussions: > > > > 1. One addresses the decision to deploy MLKEM768 instead of > X25519MLKEM768. > > > > 2. The second is concerned with the tally of support for publishing the > RFC > > > > I'm starting a new thread here that can focus on discussion 1 to > > highlight some positive contributions to that discussion. > > > > > > - Mark pointed out that I made a mistake by referring to a "Feynman > > estimate". I should have said a "Fermi estimate." He is right and his > > message shows why a focused response about a specific issue can be so > > useful in discussions like this. I made a mistake. If no one had > > corrected it, it could have encouraged others to repeat that mistake. > > Mark corrected the mistake. We now have a consensus about how to refer > > to this type of estimation. It is easier to build consensus with a > > series of small steps like this one that focus on narrow specifics. > > > > https://mailarchive.ietf.org/arch/msg/tls/qAPFBiBwPPXj0nST62FfJ3PsDCU/ > > > > > > - Dennis said that I repeated arguments from my original post and that > > it is important to avoid repetition. On reflection, he is correct on > > both counts and I will try not to make this mistake again. > > > > https://mailarchive.ietf.org/arch/msg/tls/vw685VPl4aXLWmqgOfdEzyWyADw/ > > > > > > - Dennis also pointed to an alternative way to estimate the benefit of > > deploying MLKEM768. What would be helpful would be some rough > > calculations that show how the extension he has in mind affects the > > comparison of costs and benefits. > > > > > > - Dennis objected to the admittedly ad hoc method that I used to come > > up with an estimate of the cost of the reduction in security provided > > by MLKEM768 instead of X25519MLKEM768. In light of the news about the > > Anthropic attack on HAWK, an interesting way to examine the costs of > > changes in security would be to allow for a convex utility function > > that captures the idea of risk aversion. Instead of using the implicit > > decision rule "make the change if B > C", a better rule would be make > > the change if > > > > E(U(B-C)) > 0, > > > > where E is the expectations operator and U is the utility function. A > > natural initial choice is logarithmic utility U(y) = ln(y). > > > > For this type of estimation, you have to have a stomach for extreme > > simplification. One might start by continuing to treat B as > > deterministic and allowing for just two states of the world with > > different costs C_1 and C_2. With probability p there is no successful > > attack on MLKEM768 and the ex post cost of deploying it is C_1. With > > probability (1-p) there is a successful attack and the ex post cost is > > C_2 > C_1. > > > > This does not address an issue that Donald Bernstein has emphasized, > > that there is also a risk of implementation errors in software that > > supports MLKEM768. That could be added into a subsequent analysis. > > Given the news about the attack on Hawk, it seems reasonable to focus > > first on an analysis of the effects of a change in the probability of > > a successful attack on the protocol. > > > > In the simple framework that I suggest, one can do a sensitivity > > analysis that varies the estimates of C_1 and C_2, but the more > > interesting analysis would fix those values and explore small changes > > in p. > > > > I think it might not be helpful for me to contribute an analysis along > > these lines. It is obvious that I think it would be a mistake to > > deploy MLKEM768. Allowing for risk aversion will make a decision to > > deploy MLKEM768 look worse. A neutral observer might worry that any > > analysis I do is biased by motivated reasoning. It might be helpful > > for someone else to give this a try. > > _______________________________________________ > TLS mailing list -- tls@ietf.org > To unsubscribe send an email to tls-leave@ietf.org > -- Sophie Schmieg | Information Security Engineer | ISE Crypto | sschmieg@google.com
- [TLS] Discussion about the Deployment Decision Paul Romer
- [TLS] Re: Discussion about the Deployment Decision Paul Romer
- [TLS] Re: Discussion about the Deployment Decision Sophie Schmieg
- [TLS] Re: Discussion about the Deployment Decision Paul Romer
- [TLS] Re: Discussion about the Deployment Decision Bas Westerbaan
- [TLS] Re: Discussion about the Deployment Decision Salz, Rich
- [TLS] Re: Discussion about the Deployment Decision Sophie Schmieg
- [TLS] Re: Discussion about the Deployment Decision Nadim Kobeissi
- [TLS] Re: Discussion about the Deployment Decision Paul Romer
- [TLS] Re: Discussion about the Deployment Decision Salz, Rich
- [TLS] Re: Discussion about the Deployment Decision Paul Romer
- [TLS] Re: Discussion about the Deployment Decision Salz, Rich