[TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa

Simon Josefsson <simon@josefsson.org> Wed, 27 May 2026 20:47 UTC

Return-Path: <simon@josefsson.org>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 70F9CF635EC1; Wed, 27 May 2026 13:47:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779914856; bh=KvRrh1CRJ51t09+yUOkN0Ecs/Zy3tI8J3IHjcUxxmaM=; h=From:To:Cc:Subject:In-Reply-To:References:Date; b=gckEpGkeXL1yIAPvEL5Gcn6HtGl7yB6c0KSxCIAxkFtTF0k93AeMVdWRZ6z8UYfsW zqbPkeLrXYUcOGdHGonMCeRsPe7W6RonLXpA0b6+u9C3U9MDFY1Px3vJG30UMDBPKF /OJbmgK1PIESfJkvRf9lvqpVQq2GH0Bwkdk9PiNk=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.401
X-Spam-Level:
X-Spam-Status: No, score=-4.401 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=josefsson.org header.b="vYQKKcED"; dkim=pass (2736-bit key) header.d=josefsson.org header.b="jLdiJ9pl"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uXOLlPdlwCJ8; Wed, 27 May 2026 13:47:35 -0700 (PDT)
Received: from uggla.sjd.se (uggla.sjd.se [IPv6:2001:9b1:8633::107]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id ACEA1F635EB9; Wed, 27 May 2026 13:47:35 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=ed2303; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=Mc5kfZuTOwnDC9jdaMMwcb+rGVQB7Q62qbI0nHr1U44=; t=1779914854; x=1781124454; b=vYQKKcEDlIy5BbCLAWo5cd2cjpMQLMcDsJ3avUD5p1hwtbvl6bFLYmA+VJImpi5mobKJbwfWgy1 BB34nWz7UBA==;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=rsa2303; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=Mc5kfZuTOwnDC9jdaMMwcb+rGVQB7Q62qbI0nHr1U44=; t=1779914854; x=1781124454; b=jLdiJ9plIW96LuUv/ZR9N/Z+qzl92fRkAxlDws2+p2cLabKIWWkPr2WxX0M/W/XcklZy9MH4Do2 ok8chIN8xTNmgV0clW3exBt2qZKHqBeWtqfhw7E1Q03e2iJEr8n3wjzUTaoCLQRT3rW2Hv56lY0Kb 8vu76DOIf3UakUwdqWt4T4YLkP8VxdvbN1YNEJTeyWtJG/SYr5yh1EqOOskoFKt17FQsLl2E0S2F6 sjojEYYIZ1W0yUMulStPj6Pz03+agucvJfuljz1d5jmhe0iGkVwtDXH7mV4SMbpoR38lNANLNPGlU q49C2qYkeUM9FAKvClbVkon4v1SjGgHw1vn1cNg9O3us04JKYVW/5i//PPCWdQvvRbpO0pJeW6P0U Gn5+nd2w/Ery/SA7eNiVJ7JkQwWi265aim5p5A+lHey0pr5lApMyS4XMUXYs7ba10R8OQB38F;
Received: from h-178-174-130-130.a498.priv.bahnhof.se ([178.174.130.130]:41556 helo=frallan) by uggla.sjd.se with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from <simon@josefsson.org>) id 1wSL9w-005d82-75; Wed, 27 May 2026 20:47:24 +0000
From: Simon Josefsson <simon@josefsson.org>
To: Nadim Kobeissi <nadim@symbolic.software>
In-Reply-To: <5DFBF81F-4A98-4C5E-A060-580DC6960021@symbolic.software> (Nadim Kobeissi's message of "Wed, 27 May 2026 22:13:32 +0200")
References: <20260519112813.1254795.qmail@cr.yp.to> <CAGgd1Ocy8f4HeQy-qWauAJAxizznXdXA53kWVp_FV1QUVGuxWw@mail.gmail.com> <5DFBF81F-4A98-4C5E-A060-580DC6960021@symbolic.software>
OpenPGP: id=B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE; url=https://josefsson.org/key-20190320.txt
X-Hashcash: 1:23:260527:debcooley1@gmail.com::LFkFueXmhyR5JadJ:6gN2
X-Hashcash: 1:23:260527:iesg@ietf.org::GVZTzFgpzlE5QYd5:By6B
X-Hashcash: 1:23:260527:djb@cr.yp.to::FzjI0H+73TXJyYNk:KQGB
X-Hashcash: 1:23:260527:tls@ietf.org::XVrR73+wg95JLFH0:VAB3
X-Hashcash: 1:23:260527:nadim@symbolic.software::hD9t+BTR3qizdMRH:OV9p
X-Hashcash: 1:23:260527:stndrds-inacio@andrew.cmu.edu::6YR5dQVUNZud0Jhi:eLec
Date: Wed, 27 May 2026 22:48:35 +0200
Message-ID: <87v7c8lgt8.fsf@josefsson.org>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Message-ID-Hash: TQPJTLR6WHQACN5233KP4OQXM74RR373
X-Message-ID-Hash: TQPJTLR6WHQACN5233KP4OQXM74RR373
X-MailFrom: simon@josefsson.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: tls@ietf.org, "D. J. Bernstein" <djb@cr.yp.to>, stndrds-inacio@andrew.cmu.edu, iesg@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/HCJDS-ihYQQF1aUKQohjhLZ1lHM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Nadim Kobeissi <nadim@symbolic.software> writes:

> Signature schemes do not have the same compromise profile as key
> agreement schemes (I wrote about this [1]).
...
> [1] https://symbolic.software/blog/2026-04-13-hybrid-constructions/

"Soatok’s central observation is one that deserves wider uptake: the
harvest-now-decrypt-later (HNDL) threat that motivates hybrid KEMs has
no analogue for signatures."

Repeating that statement doesn't make it true.  The analog motivation
for doing PQ hybrids is Man-In-The-Middle attacks.  If your non-hybrid
PQ signature has a weakness (e.g., implementation bug), it facilitate
man-in-the-middle's.

There were times when man-in-the-middle's were as common as
harvest-now-decrypt-later are today.  I believe that MITM's are
generally worse than HNDL attacks.  Adding a pre-PQ signature in hybrid
with new PQ systems is low cost compared to the risks.  We did that for
PQ key agreement based on the HNDL argument.  We should do the same for
PQ authentication with the MITM argument.

/Simon