[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

Jacob Appelbaum <jacob@appelbaum.net> Sun, 12 July 2026 22:54 UTC

Return-Path: <jacob@appelbaum.net>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id B0C55115862F7 for <tls@mail2.ietf.org>; Sun, 12 Jul 2026 15:54:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783896867; bh=JyRRyOlCaLZKDqx7sZ2+8E8ep92LNpyX+eMz5fR1m9o=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=SMbqB/z5S+VCvP87AwzhLRvuzbx3CjhpjWirzpyUqdFNVVH/LnmuPGYSa1Ic3JJx3 dExz9OieO2VsmWYXSzxsvgTQozAKzzq9F6f0PV20N6ltvhhUHK+9n0pR+ZvMsug5Wz WbI+hl3QBwYFq/5cLVkUoZS7vz/wXeOspaRw7u7c=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=appelbaum.net
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iv72WcOGFuYS for <tls@mail2.ietf.org>; Sun, 12 Jul 2026 15:54:27 -0700 (PDT)
Received: from relay1-d.mail.gandi.net (relay1-d.mail.gandi.net [IPv6:2001:4b98:dc4:8::221]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D3E48115862E6 for <tls@ietf.org>; Sun, 12 Jul 2026 15:54:26 -0700 (PDT)
Received: by mail.gandi.net (Postfix) with ESMTPSA id 9D2C43EC0D; Sun, 12 Jul 2026 22:54:25 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=appelbaum.net; s=gm1; t=1783896866; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=XSlSrGFLydqy99hOb4aE8VzoBbN7c49jBmtJOXds560=; b=S/FF5IlitYDRWHwlwiGgPLU6eIVEYuUMUIyPQlXQEMat8Ll+f7EK/WxMzln1kQ/c9TOIbw bw/fvudgT3AWHL1pZvs+DHyD8jwPwPrYCh+IQpaQ1qDbbYakYL4wR4qLspZaKZHD1QiOw2 3pXJmd5Jznp0ZczFjJUXd12wfRXpHz433nYv0PflItQZyNkwtM/d+7s0gRFnY1PqWTFKlp P1ezeVQrRtzHf/1g/0JNj/xZslMoTYhiGzv9whR85DExafIEBq4Ym9Go1K/pfsaPqpqBFp Np+125HY31s9K3nsO1JN2tJYRB6fnDsAZpNKsGQFr28idZjIHMWJUjMMPVclfg==
Message-ID: <09f62cbe-58ea-46f3-81f4-f0711cb4ef9e@appelbaum.net>
Date: Mon, 13 Jul 2026 00:54:14 +0200
MIME-Version: 1.0
To: Daniel Apon <dapon.crypto@gmail.com>, David Stainton <dstainton415@gmail.com>
References: <76f613e9-e952-40fb-a6e0-745392575b91@appelbaum.net> <ak6yTqUFo2WJ7Q-m@akamai.com> <ak89AMLg_ZVnvJ8Y@ein.win.tue.nl> <751a6f2b-0c8f-477e-b711-23921a2ad8f7@streamsec.se> <ak9XauPVYm7OA65k@ein.win.tue.nl> <92e0e621-8efa-4e8d-a7ea-4183981616b9@streamsec.se> <0e91ce21-028a-438d-9ea8-a416d3d393ee@appelbaum.net> <78945c98-373b-4041-84fc-79689d4b67f1@streamsec.se> <70756c21-7ecc-4f83-89ee-db9a69331a0f@appelbaum.net> <655d7b49-e099-40a5-a04c-546a54d6ce57@streamsec.se> <6d3bb45c-4bf0-43b9-a9e8-7e4632eebe94@appelbaum.net> <CA+iU_qn0XUYY8MEgyEOZuNt=bsHoBd1kKOjyNuFAjVOYG8FoPw@mail.gmail.com> <AS4PR07MB8825C6262BD443833F31A2D089FB2@AS4PR07MB8825.eurprd07.prod.outlook.com> <9f8ca8d5-c6f8-4c17-bc0f-e383c8f8e0d2@amongbytes.com> <CAFN1edp0=Yy5fpfRaPDEQFNNJCFYc40BGKX+YQ60yGSm5YVOzw@mail.gmail.com> <87v7akqlh5.fsf@josefsson.org> <CAFN1edrHiiqRELAVmwo_8GUuZy+1XLDbv-SJ1vXO1CXLOASBTg@mail.gmail.com> <CAPxHsSKMYhqFudK7q0QYODZxA-SnSQCkJu0vnQVJYkXk9+3PNQ@mail.gmail.com>
Content-Language: en-US
From: Jacob Appelbaum <jacob@appelbaum.net>
Autocrypt: addr=jacob@appelbaum.net; keydata= xsFNBFXlpJ8BEACnFzfarolZLsaP8GCk/ytNIUk6+GstAAVqQdHprkx3TfZl5/tUQC7a9oz/ +QD93U2Zq0RVj6/fAiZeV8X0TadVDcYo2KNk693EC1qwJwGMOMiYKEqAS1PuNSzQqvtyqlm9 0TrGL2qVKqIGHP1CXdV5QAlqqvpG5AVaH49H+cLmzkGdnz8Dp89zcmQ43EPvBxnHSq2P3D8+ aMgICQmzjxnqzX4X1w45EqNIv3STmTDS5HxhISu8KpRuWXvAm1XItCQGzJAq/ybEW60NpH4q yZsPQ74w6K3kECwEwUrO3yCScKuWFFs2qIdvditoWRIZQSErZi0VhMMoxx1n0y6dYffNvds7 c7j5n23KZ++8pZjqdql/cFez7o7RBn+tiTO5jJCFkhgDK51jQxec0d0qjeQvxCaafsM0q8qJ n8icW16yzOg5Ace6Hg+l+0DicqiwYYW1807xd+BGT4YqagdbtiB7UPcfEzAo84QlqYjqcKqT 3tKFf6SuetGffEW9f3XP9y19IqpNNRJDdWDrz44GeH86j/XE01buJE4evjvFaoUAGUYoB3Ul ZjtKj9bm1NpeKBmkgD1pqR4cWFf9tRJf31ztgd6PZBzuZ2fJkXShbz0wIVL+wDAX4X/fyUib OO1tgf9c+BYhRn8LTA9JtfAdm1YnscSK8pjLiD4u/Hbqk0H0WwARAQABzSVKYWNvYiBBcHBl bGJhdW0gPGphY29iQGFwcGVsYmF1bS5uZXQ+wsGIBBMBCgAyFiEE4R/M4wW5yEZ5Oweu2aEf fpkhXaEFAlXlpJ8CGwMCCwkCFQoFFgIDAQACHgECF4AACgkQ2aEffpkhXaHVCBAAhIJNeG8v q9SdwSmolgv4cqBOXYxuiH1GkZv4tbUHJfmg+msXFXY77Wd3G48ltM4srqCmfwGCGu2Y4Ggu iU3XQPwyQ7KU49WFU5s8ZFq0m/pt2chIlI3uvenvsxvS1GkljOrhpk/flkdtdqDb60GZizTZ JVnXMNuDmvTr97ltQ3q9vrp+tZv/+I02uhsWQGTQrSdCjOUYNtO3C4S/GSMDZ7Jzf6X89s1z /O7os4YCZx3qVxR9IsLqkFi/TyVsROOiIzea0oPifaO94Cg8kkEc9eYLfJwfIW7A67SLbiTd U4tkxT7o0SgAc0aHB24xZKkoLSVAXW/GyJlq/K8aB5Z3RYWibe4i4aCa/uJDaZwACLapU5pp botaM+yisguEZo/t10KGbkamwPHeaGi/UPLxUjR3TpeGWF31/xRe80vtVxaBCOy1+6W88UBH 3hFwb4mnH1jmZUKkjX0xAdzOf9ry7B/JLTsOSEoatj2IrmfNhM+66x9buLq8nPDbx4c3gfvd qcMbvkJDzGrGIF+dfhaGL42vBk69wziS6VL9eUZG6cDqL3yd+UqioFELV3n0I8NJR3QeOVkv nibez4PfpYvgvFiEf+0sPlUnEN6axrUdZNtKSm1+Lw7NSXVWwMHtNE9jn7fXaWIZ6thgHaoA ES5uVLQYwkpcHQ4UcUMuGGun2M7OwU0EVeWknwEQAL1jVf/pnmjEHYW7EGbhHy5C8lALekKt ubPT9/OPwY1rYXgjPYC9PMw0gTVpYVxotBRIY3NCay9Jsm5QtMX3EnkCP0dEv8EWU+o2WlEY JtwQFC/TQbwaKBaMgHWpUJFD07KdKMp/92CUMOMHEqToxv+TI+hidbRMRt/McYf0V9mrzE+5 KmQESfTSXPtV32LyslOMpeDIOa/XS816H2jtw4Mzb+VF0EdlqCvltovUIr0ghh4HSaOVQi8t bjax2F8NKM87yIhszsdneiDIH7Rk9ZznWfC5IMkLWCejPh1EZlU3zNzv+FFdDREaQ54SezE6 txW86UaBvwWUOAdgdYw6cDXBeAYfn90O6v96WxLUthfomAHb7kjTSG4ngOcoiOq/i/wOFryR G07bhL+WYA63hvqIM89DHfmhWhUsOkiUDbDK9xOABGQ7+UJ39r4IaNa4IUn/hSmyevncyJYJ MdjCDSruqmY4V34d3Q2cnAy+1jf8Cm4opOYdzAtuHNfjWLbXksO2z4mncee4NdKlpvD9rZCD 6iSEsdRV5UuiP8oBEi/4q1RNn8abCmyWUQXqdo3vnkV3Bgl8GnuS6GGEzVJq3pC8CqjZ97V/ +YHjgPcMUL2RCc9/QRfR71BjYsllLwlZtl85zYcbNORDUzVOe1Qg+k8DygcDPAuvFwLzLn1+ MGrZABEBAAHCwXYEGAEKACAWIQThH8zjBbnIRnk7B67ZoR9+mSFdoQUCVeWknwIbDAAKCRDZ oR9+mSFdoaX7D/49q6ALUSfwFyanXeX4YLfndeTCJd7AiGGlYVFzESkk4DUEy68Y8e7gYs4B 2YDpRzDgJrx2A61u7oSHv0b4hzwUJ41TyBbE4D2hR8o9qnAX2jpwWPinjCInbinUGkpfSZxn b7Yn6/p2kw5JeWGFlBJEyz3/g5ebq0qrx/OdpS9b8Jxlde3Le0jU+753BHV0ef3JfCTH6BuM 2T8Cv64n7vkhZWqUgnB3rEXIzq+xbYrpLJTeapwSr3k+xjI5YpmiTjUD8uCwzSJoq8x5YnXV CjA7TNGvhANFu1j5ElnSf4I6mje3gL+MK8Fw75SUZqdTL73rXstP2HqzDIV+19w8JA25h/Tm CcCYu717hq0kJVk2wiFbmhJHj6kb0tgn7xCCw9xe4g4T9K5YL4UiSpL+zxIb1BLuaYoYtPXP RcX0NkBu+N38Tvpng6HrBGFHQzTv4GB60eDm0A5+zbQe4RFmR5G1BdBpeYauNbtA9gAhuBZy DJPEu/qlaj3Ptk8MZiLFeHTZaBj9O1W8NuqK88k8KYkV/gd1Vni55bMee4CAhfGnHedDySGf mzbNFr/QAYmT3flZg7xnVJWSF904U8QAN1lejrC2dsj6TcaTHIzf9T3SZQDvc6e2ocYu6VeS Ctn4q1Sm/1ctbXEKhP8Ye1RRRwO0GvxJACvuHfoDqeZI98haZw==
In-Reply-To: <CAPxHsSKMYhqFudK7q0QYODZxA-SnSQCkJu0vnQVJYkXk9+3PNQ@mail.gmail.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-GND-Sasl: jacob@appelbaum.net
X-GND-State: clean
X-GND-Score: -106
X-GND-Cause: dmFkZTFaUwitzzugb5PVhe/HzzsQnDlIusy5D56pa+cnr/2ZtCQ5sT0T7t7LT+h1JjFafvN423/v1Rv2W4Hbb9KGVxjZV2V76zI3eeSwCDobqwu3Av6ZaoOkB9w1kmkdrdsQoo5+aYYxJvoQKQ3OLyC7JbyADMeC4ukZfaIvH+xlSriJGtkS3eurMKnsSAvFlJKEo20NbjFKwumaix0b4k2AQ/gX3kPmGMzX10vakxGRSWJy8vLdCsWkkJFfZ7a8ZY/5ereGZHIv5sMluvVP1NFaRhpzrSg9Oqas9ph+e5avhvw1JjZXyV4L47yNIqXWbKJZqpuyjSNmYevzHaHqfGGv6RGFMpb0WSGZCa9EDk2DSwS+GY+bYFTLNYBxP8/Lg/yW2Nsv6YEua/EN17z6h5C5vrDLyHR6ot9Ygi8tvcmgGDhSNWuFxgDYSDIpRhbPOQWOd2J8fd8Ujw661+WyukWSq/Fv7rHA8Go4xR6FUdDk/kZ8y4yjXMnGhxb3uj1kVpZVU2EfaRf6fCyLhNIlAYwOeRrY61K/a3j++bLpNwK1/kNXTOjscO4dVghVnySdtB89O+fRWTgz+daPFjhJtt16FpgdLGPeVegn6eZlHUmwVN5Rm20w0jWgT8pqmTx0njibLP3J6CqWtq6ruzHXNRL5wWHnW+/6l/f6vw0gkxAXlDYNwg
Message-ID-Hash: UWGTHK5M5M5GNJO335Y7YSJNZ6H6LGSB
X-Message-ID-Hash: UWGTHK5M5M5GNJO335Y7YSJNZ6H6LGSB
X-MailFrom: jacob@appelbaum.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/G3K3LTZMCNIyMefVcFlt27B5fEc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Hi Daniel,

On 7/12/26 21:42, Daniel Apon wrote:
> Hi David, Simon, all--
> 
> In a very general context, there have been well-founded warnings
> before about taking legal advice from a public mailing list, e.g.
> whether a license permits this or that, etc.
> 
> Speaking for myself, to address the weird crux of the current
> technical issue (and again: I am not a lawyer.):
> 
> The licensing effort by NIST was intended to provide patent-free
> commercial access to NIST standards. It seems odd, to me, to see
> this turned around some years later, to question the intentions of
> the NIST licenses about whether one can hash this way or that and be
> compliant with the license that NIST has granted, for free, gratis,
> to the world. Anyway, perhaps this is a question better asked on the
> NIST PQC Forum than the (very specific) TLS WG mailing list.

It isn't weird as much as it tracks with using the patent to achieve a 
specific singular (sizes aside) implementation outcome rather than 
encouraging a variety.

NIST won't provide clarity on the list when directly asked and yet it is 
such a simple question. Many people asked NIST over the years including 
on pqc-forum and in the official comments. Still NIST has continued to 
not address the issue. It makes NIST look like they can't address the 
issue because they don't want developers to make a choice that for 
example, deviates from FIPS 203.

Sounds familiar... oh yes as Ken sent in an email earlier today!

 From Thomas R. Johnson's declassified NSA history:

"(FOUO) Once that decision had been made, the debate turned to the issue 
of minimizing the damage. Narrowing the encryption problem to a single, 
influential algorithm might drive out competitors, and that would reduce 
the field that NSA had to be concerned about. Could a public encryption 
standard be made secure enough to protect against everything but a 
massive brute force attack, but weak enough to still permit an attack of 
some nature using very sophisticated (and expensive) techniques? NSA 
worked closely with IBM to strengthen the algorithm against all except 
brute force attacks and to strengthen substitution tables, called 
S-boxes. Conversely, NSA tried to convince IBM to reduce the length of 
the key from 64 to 48 bits. Ultimately, they compromised on a 56-bit key."

I predict that you don't agree that this is relevant.

As we discussed previously: we don't need to discuss the lattice 
hardness assumptions if the Adversary has an advantage that satisfies 
their attack before the lattice issues are the hardness assumption(s) 
needing to be solved.

Here is a fun idea: someone should call their State Senator or 
Congressperson to request an answer from NIST. It would be much more 
problematic if they refused to answer in that case.

Kind regards,
Jacob Appelbaum

> 
> --Daniel
> 
> On Sun, Jul 12, 2026 at 3:11 PM David Stainton
> <dstainton415@gmail.com> wrote:
> 
>>> The NIST Kyber patent license only grants you a license to use
>>> ML-KEM when implemented according to NIST specifications.
>>> 
>>> If you deviate, such as by taking the defense-in-depth approach
>>> to hash m to improve robustness against a compromised PRNG, the
>>> NIST patent license does not cover your usage.
>> 
>> Hi Simon!
>> 
>> I appreciate the warning and I am well aware. Maybe you providing
>> this information is helpful for others on the list but it is
>> simply not relevant to Katzenpost since we have no commercial
>> pursuit, we are not titans of the industry, and furthermore we do
>> not force users to use any particular KEM. Any KEM can be used via
>> specifying it in configuration files. Novel KEMs can also be
>> created via our KEM combiner. In light of all of this, I am merely
>> stating that pretty soon when I get around to it, I will make a
>> modified Kyber that hashes m. And this will be made OPTIONALLY
>> available for use in Katzenpost if users choose to use it; and in
>> this context "users" means mixnet operators.
>> 
>> Best regards, David
>> 
>>> People in the IETF used to prefer patent un-encumbered
>>> technology, but things are different today.
>>> 
>>> 
>> https://csrc.nist.gov/csrc/media/Projects/post-quantum-
>> cryptography/documents/selected-algos-2022/nist-pqc-license-
>> summary-and-excerpts.pdf
>>> 
>>> /Simon
>> 
>> _______________________________________________ TLS mailing list
>> -- tls@ietf.org To unsubscribe send an email to tls-leave@ietf.org
>> 
> 
> 
> _______________________________________________ TLS mailing list --
> tls@ietf.org To unsubscribe send an email to tls-leave@ietf.org