[TLS] Re: [EXT] Re: I-D Action: draft-ietf-tls-mlkem-00.txt

Paul Wouters <paul@nohats.ca> Wed, 16 April 2025 18:16 UTC

Return-Path: <paul@nohats.ca>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 155481D34083 for <tls@mail2.ietf.org>; Wed, 16 Apr 2025 11:16:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.398
X-Spam-Level:
X-Spam-Status: No, score=-4.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=nohats.ca
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kyvVaBFE6kXB for <tls@mail2.ietf.org>; Wed, 16 Apr 2025 11:16:32 -0700 (PDT)
Received: from mx.nohats.ca (mx.nohats.ca [193.110.157.85]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 0FA6E1D34077 for <tls@ietf.org>; Wed, 16 Apr 2025 11:16:32 -0700 (PDT)
Received: from localhost (localhost [IPv6:::1]) by mx.nohats.ca (Postfix) with ESMTP id 4Zd8Ns4PsnzDh9; Wed, 16 Apr 2025 20:16:29 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1744827389; bh=zSKfCDrNan6CnsrSGj+WIZPzasDNAuC7bFos0pIqANQ=; h=Date:From:To:cc:Subject:In-Reply-To:References; b=rgDTMLfgfnqefIc3T3dwjRievY5LDbVCrdKrKRTaBmxTXieOxBmHj2xikGIc9BUfs hXy1ibbzhPm1qAdbUw+pXCxABG7s9w7qxovqvaJGGW3oP2eLUkpaJuLCoEQh0IDkFO KLZZkoGO0YVy1GcjNQ8ikW3hGZBe64wzoDHWY4k8=
X-Virus-Scanned: amavisd-new at mx.nohats.ca
Received: from mx.nohats.ca ([IPv6:::1]) by localhost (mx.nohats.ca [IPv6:::1]) (amavisd-new, port 10024) with ESMTP id WVbZi9gXe67s; Wed, 16 Apr 2025 20:16:28 +0200 (CEST)
Received: from bofh.nohats.ca (bofh.nohats.ca [193.110.157.194]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx.nohats.ca (Postfix) with ESMTPS; Wed, 16 Apr 2025 20:16:28 +0200 (CEST)
Received: by bofh.nohats.ca (Postfix, from userid 1000) id 81F8A14F65CB; Wed, 16 Apr 2025 14:16:27 -0400 (EDT)
Received: from localhost (localhost [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id 80E8814F65CA; Wed, 16 Apr 2025 14:16:27 -0400 (EDT)
Date: Wed, 16 Apr 2025 14:16:27 -0400
From: Paul Wouters <paul@nohats.ca>
To: "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>
In-Reply-To: <BN0P110MB1419C6B51D12BF8F3418280190BDA@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM>
Message-ID: <c941fc96-2e51-5591-a14e-eb63ababfa2a@nohats.ca>
References: <174482144256.1417643.12778721014959621161@dt-datatracker-64c5c9b5f9-hz6qg> <CAOp4FwR=RGrWiyVZ392a4myf_FeEGtHME7fOok31b0oeeMQ1Fw@mail.gmail.com> <BN0P110MB1419C6B51D12BF8F3418280190BDA@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Message-ID-Hash: WPDGS4UE7SVVFRHWU34WNPYROWDYQ57R
X-Message-ID-Hash: WPDGS4UE7SVVFRHWU34WNPYROWDYQ57R
X-MailFrom: paul@nohats.ca
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [EXT] Re: I-D Action: draft-ietf-tls-mlkem-00.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/D_Ooo8arh1Gd275VYYwFBJvSFYE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On Wed, 16 Apr 2025, Blumenthal, Uri - 0553 - MITLL wrote:

> Sure. On the same note – how do we know that there will be no new research findings about ECC? (Besides the fact that once CRQC is built, it becomes useless.)

Not uselesss. It would still be a good anti-ddos / cookies technique until each phone is a CRQC.
Especially if you do an ECC exchange before a PQ exchange like a Classic McEliece. This is
what the Additional KE (RFC9370) facilitates for IKEv2: https://datatracker.ietf.org/doc/rfc9370/

Paul