Re: [TLS] Before we PQC... Re: PQC key exchange sizes

Stephen Farrell <stephen.farrell@cs.tcd.ie> Sun, 07 August 2022 21:39 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B9338C13D086 for <tls@ietfa.amsl.com>; Sun, 7 Aug 2022 14:39:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.009
X-Spam-Level:
X-Spam-Status: No, score=-2.009 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7ILmGLQfZEU2 for <tls@ietfa.amsl.com>; Sun, 7 Aug 2022 14:39:48 -0700 (PDT)
Received: from EUR03-AM5-obe.outbound.protection.outlook.com (mail-eopbgr30115.outbound.protection.outlook.com [40.107.3.115]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 37984C15C51E for <tls@ietf.org>; Sun, 7 Aug 2022 14:39:47 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=U7ZWVCYLY9bBOFMfVOPnDMiuhER8bCMoIvUpC56R3xb2KY+y9hIjGHs9ONsyJdcNzOqcN8KQyCDOv+Fn7LoOhef0osPZet6NdtIWwfQCdM+0qOqc+PE89kM3QWc7cu3/FPwBLTkyTW695UEI0oPIIwXxDB+PEfgfT6fr+7s6j3JhEI/qR2/ATuLGUcUPtJVcOwTyCqMw36Qc3oHTrxgz3OTNquieS82WoVkjdanFhnyF6ojHIRZf9wFQljUv2930FM3psM/joimK0Ao45tM8dh+OxPhlybRHrrivZn2FxNr8GIN8dOiRTf7KkYVt2kgGdRvss6q9FuPJqQ4WI/HH6Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=P5rap6d0A2p9hg7tAUBOWSEIgj+509zPwgcUQ5tpk88=; b=a9JU45y/mv39qm9NCiMT3l44U9b+X2uoTvfe5C0ZkxGVnNfAPMI3U8KuPczW4siluX5cbKm2OihKmRs1ShNgHfiEN4sb8z/LXqzTW1/6sKimlmqWdMLZpXv14RPP8SMvZuhLLBOINwHnj1WuDDZ6f/U3DZJrLTcAdzgFtQOwNDgKuYaP2/tPYk3bchVNIVhc6uP7QEHQtlo21AK7x4+AqVrJOHGJfeNb2jX8o+1QoXxyKd5GfP4bquoECGQS5VOltRwBkcNZnERjrmbAFTypg+RgiMK6/GAM9scqugJmpyopSq6kZTGXQeBD22xwMHjjoJqGPUlxPdlNmx5pv2T/Pg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=P5rap6d0A2p9hg7tAUBOWSEIgj+509zPwgcUQ5tpk88=; b=Mmo157ntn7GRaDQ+IjmxV2dZpTFbS7eHrNUwoQt252VtOwfZXv6Rrh6lpboapA01Mwha9RdGRu2oJ8PA6wpHn8nE88Jmdps+rrK5pSGzzdV0J2p4sjFSh9uABjHq8KMo0/9zK3APP8Ms18NzKVjwP6hKHOMXTo4JZL4G3dYYVxkn8r2HlDO686/yxjYjBATS8sdr82niUV5iv1m6sqy/NuiX+AXynY8hma6/Y2xwO5kcM5Gt2GnhhLYiApQPvaNI4vLh2I6H+uaEFaUcd/MUtyqBEEoDnSAOcZ04BE54lhV6eX4sUrEX1S/3DI8QyBc6zoI9pjQMYCgQsUZE4D5ULw==
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15) by AM6PR02MB4454.eurprd02.prod.outlook.com (2603:10a6:20b:6a::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5504.20; Sun, 7 Aug 2022 21:39:42 +0000
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::34b5:c457:b614:b0ac]) by DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::34b5:c457:b614:b0ac%7]) with mapi id 15.20.5504.019; Sun, 7 Aug 2022 21:39:41 +0000
Message-ID: <45ec6424-86d2-3654-3354-e23401a141ea@cs.tcd.ie>
Date: Sun, 07 Aug 2022 22:39:39 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.11.0
Content-Language: en-US
To: "Scott Fluhrer (sfluhrer)" <sfluhrer=40cisco.com@dmarc.ietf.org>, "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>, Phillip Hallam-Baker <ietf@hallambaker.com>
Cc: "TLS@ietf.org" <tls@ietf.org>
References: <CABzBS7nsbEhR-bmHG_ViSJFSH-0_5p0O3vKndS4+wFR=iGQzhw@mail.gmail.com> <CAMm+LwgAzb4t=awzpU4Sb5j7Bf6DuR3u+23n+h_C3Pnsin-SHg@mail.gmail.com> <8383756C-5595-4028-9E5E-8B758147ED33@ll.mit.edu> <CAMm+LwgHNL_aHqK+TbdBf=xJBPftjkXL_=isXUJB+mbiUc7_Lw@mail.gmail.com> <58778bee-ccd8-3b6b-cdf3-7392cd6f3187@riseup.net> <CAChr6SxXVzKptFzDEczOUzVf+LGSNxY=rk45DgXceg_anA_SPQ@mail.gmail.com> <20220806051541.GQ3579@akamai.com> <CAChr6Sy3vGbcDCDXWOGNwLQgwZZG_z3HTSgz54Ch2_vurF++RA@mail.gmail.com> <CAMm+Lwj19zmbPo+53Zk8m3AOWPGF8mhyB9SPTVP7mP0DsWpPzQ@mail.gmail.com> <SY4PR01MB62514622B4DE2AF47F1B1DD2EE609@SY4PR01MB6251.ausprd01.prod.outlook.com> <CAMm+LwhdxdWJsqCW295Byu1OFDqbTnJR91MFdBHAY6tkk59Jag@mail.gmail.com> <795BED30-B499-4E64-915F-4317C629E908@ll.mit.edu> <DM4PR11MB545560CE4F54D5B9B3455BBFC1609@DM4PR11MB5455.namprd11.prod.outlook.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
In-Reply-To: <DM4PR11MB545560CE4F54D5B9B3455BBFC1609@DM4PR11MB5455.namprd11.prod.outlook.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------fD9LZ138cLs5nvrGeQ30PutJ"
X-ClientProxiedBy: DB8PR06CA0053.eurprd06.prod.outlook.com (2603:10a6:10:120::27) To DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 0917d824-fd0c-4299-2d4e-08da78bd5596
X-MS-TrafficTypeDiagnostic: AM6PR02MB4454:EE_
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: HiMwUGG1GZDXBd4We/CXT5U/K+4PXq8ZzAwC9yIkJkPQK+XsccNbsnS7Z1R4ksWJ3DPjHY0ppaUoYaowxTsvQRmnckXdy1Qk9HGkZsCFQmblacH674rpk/GXx7CwjmerHemK9FHi20yBQ21siFKqBSBm/YliMtasrZ8SKy9gBzxAMdisFUjVhF7O3LlcT+8bXr7rz1zbNJsmwHh8I+s4p8yqejJcjxkcdQSCmAj2n1kOpXLwhCJgXTN1mbSm+oN8nJhGxKIlv8TPzeGq2EojVpCgL+bq30+ImlW5LfcSsSme6qkz+BJsdcC5sSpPa5Pxs5V87/rJc80Y3n7TCYdR/jrUKzA2XSMVZTIZ+igKAQt2ABxAdrdKneq5C40/1RYInqH1psPqPoupDX1Iod4rRoHSrdt8U3co7YLvVLuKsqel5UCeGqLVP2Qk2/Br36HEw4FK05eTRMOQKrvyBfH0JdaH/AHeNIaez2AaRNmZhozET9t0F70T5p6XgRRH650wl+nvHvEtsZclKv396c/3Qrmn8tMJnKT7gupxTtjPcK5+2gqlr0vOtGm6vy9d+asrWpeOBn+69zwgtCATgb6IT5akGq9XT0QbM7AOmbvm6gUn74BXzeWuXI6QxICOhIKd5vUXLOFQcN3pqXth9CQ0PT4gOa3gz0Vyh8F40C+1wxHTICDMhW0ZtYCZEANgewZbENB8KRO7Zned85QKSYTgvrP9wBwZoblz8AEn5+purcDFv6IWOuWKEC6UeDEkIQVq5j3zWdENjrsSY6uA0+3F5/gjlUzlRfF0Kkmc0rtCrL3IL9OfG2pKzCK1GRQwHHbva9sCtRYsQENqGAwyADPGkw==
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB7PR02MB5113.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(346002)(376002)(39860400002)(396003)(366004)(136003)(4326008)(8676002)(2906002)(235185007)(44832011)(66946007)(66476007)(66556008)(478600001)(6486002)(786003)(316002)(36756003)(110136005)(45080400002)(38100700002)(41300700001)(31696002)(6512007)(6506007)(53546011)(33964004)(86362001)(5660300002)(8936002)(31686004)(186003)(2616005)(21480400003)(83380400001)(45980500001)(43740500002); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: xmdE9mvVZmUT4ft5EVW/B0WMA6ZC9TXrhGimc+iGbLWIH9+E3BfzDDnfQ03MOVT/Fgf3uYntfew5kS14tqNcLypJ+flZoFadHVkBBA4X/jK/ubYnZb1DafJpLK04V6rawQ4oYJgtoAHqudd5KYZ4q08dOcHaMwtxi5LsBlbMTHJhm7to3b8Vxr/7RLbDZNelnwHrSpFQWFGNmL1xc/sWISHKdkn5zyuh1ldM5BcrZ7w8XAt3hRwHlJb6JlzNUzn4aaH4l+eDvDz6B9+i62l1C8oOqrSted2b8dzactTPDR4rD0HCyrugDrvMjgDZQ9n9FYZm6pNtWzpHQxiURk1/8lejILTm0i8QjPxln4IhtWduwlWclYekLaSjr7vTrXlz3srqzfi66SK1g0IYYNNa2txSloVMcP1mTm6/4AfiNBRJBRQRz5krvgfYeXwtUuk/0OXuRTSl4CzYE8qMrj1Ze6vZc6uNMDg+/dYT1PuR8kXL0wIS1RvUU0Wg407yRnxERUYYpBYZJ/psR+2MM8mYpqApflNfA2zalBDpqrfqV+JUjLfLEOGkjmZ1oWqtOfbPWp52xb6XHstPwekAx0y91XXYc7JwaYLoAAvJ/srJFnPxjYQH21dxwo6eryi7XKzTp6njbzadqhtMEp9pshwk0t4c0AeEMrz37Ip79UQV6/D5odeMFb+G7WQUSlspGjyb7eC9C5wk9NAv5EO1UZqA2BS4vMcZ/oUs5rgbwLsX4qKokg7WG/p9AuUZG/GunHr+SEfNS15KrGP9Tr/pv9Jn5iXnVSOiIzUPnLs4MJtXi9erz+9HwzGws3i1h7eXeVtWGN5oH+q9iVx+TE7jCm5dOvmDSF2PJVTzUBCq0AX71INk69dHx8B6dhslsxqjDq6VHjZ1yHdw2NL6zQgPVg0Kw0v22TYeyviESxAdBFJi+V7gqz6YKouf/OPuT0id9QybGz5KZkpWwZwib4tPPtLP0U26aPK6JfHqR4dMXpkHmO+ep1/8FybXteav6kW1vufSaqtO61EOKMlZI0ELnZF44we8YxfkBjQjxLiqVpK3WqG9T6ohwZztPHiKO+hqv4ydeKhlvqfOh+QVWbejplh7+et47ATav5R0d16+lZeLNUqhvE83VjX5lxJdOmEd8g/MfQpP1HZF/dyWMI53M4RoYZ7x+GrfcGmQXWisOlPnvx8YR882Fs6nFWHiJPFsbOQ7EF0MvQAKR6vdZALHmy9vrBHrUQJSOdwWRW8DtdpSAcWWhWWBLMAonKx3+Q4fLYAvl5476Qv5Ldu7XJ/Kv8Pkh3x9CyhFScpCUp86rFMfX0deCciqOFLMlYUHbvsbXO7uzGydaS7vESKdUdEjW17OZ0a9qGBt0hzrEVLuGj6xzPJccBkaWQnThwPcYaU53+pB0RqyU035qaGNwff8VkoG2ke80J7sCd/fhToSPsiL9Z6tuPiL98SVhbu0aJvtEMwcasnxvzNqPbiiKnWh8MaN6EqO2eja44r9rGcHAi50NQUyTiuoGYfzEwmE/+73QWt8oQ5P5N66Ez4AlrdryZcIqS78ZbyE0p5/DQLzBIeU3UyDyTbxJ8SQsYqMJj4qLGzxkFpAuE4HaleirpwfCLf7UaC4RHYXHm4vRV3UezFNirZ6jGbLBKHqirqRDUOf2wyg
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: 0917d824-fd0c-4299-2d4e-08da78bd5596
X-MS-Exchange-CrossTenant-AuthSource: DB7PR02MB5113.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 07 Aug 2022 21:39:41.0778 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: OwuXQeXOBJSuTLKgGiwRamTNx/u8A+JJfQQXDcC+MG3yuiABL4fUfVIVmiuZKx1V
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM6PR02MB4454
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/IJN71NNAFIbmxefTWuVWrBCR6eQ>
Subject: Re: [TLS] Before we PQC... Re: PQC key exchange sizes
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 07 Aug 2022 21:39:52 -0000

Hiya,

On 07/08/2022 21:58, Scott Fluhrer (sfluhrer) wrote:
> Hence, what we are proposing is no less secure than what we are currently doing now.

Well, except there'll be a whole pile of new code, which
is a fine way to be less secure.

Now for key establishment that's not too bad perhaps, but
when I hear some of the certificate proposals (in lamps,
not really this wg), I just shudder.

S.