[TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa
Ilari Liusvaara <ilariliusvaara@welho.com> Thu, 28 May 2026 12:22 UTC
Return-Path: <ilariliusvaara@welho.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 77530F6999F9 for <tls@mail2.ietf.org>; Thu, 28 May 2026 05:22:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779970936; bh=r44ofV6K06htJbKBEy3izgzLXBs7aT9PksK12IYwA8I=; h=Date:From:To:Subject:References:In-Reply-To; b=Ai93B8llIJPB5WhjoXLKlBNG56cbWkylKXBdL+lGhg7JE+Lp9DEHs4/kB5kicgZ+k 207hFcLlQY1RhRobmcxLJGXSqEHZN3M5/qEyOkKu5XvowTKApIsgNTauoxGNC3X9Dc Dmya7cYm8CEZ1JzxsjZ4jPy0rXIhhTDlgfAQ+ZRs=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=welho.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 55QdU7uGW_Ov for <tls@mail2.ietf.org>; Thu, 28 May 2026 05:22:13 -0700 (PDT)
Received: from smtp.dnamail.fi (sender103.dnamail.fi [83.102.40.157]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 17A9EF69997D for <tls@ietf.org>; Thu, 28 May 2026 05:21:49 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by smtp.dnamail.fi (Postfix) with ESMTP id E39DA409A3AD for <tls@ietf.org>; Thu, 28 May 2026 15:21:48 +0300 (EEST)
X-Virus-Scanned: X-Virus-Scanned: amavis at smtp.dnamail.fi
Received: from smtp.dnamail.fi ([83.102.40.157]) by localhost (dmail-psmtp02.s.dnaip.fi [127.0.0.1]) (amavis, port 10024) with ESMTP id lwenc-6yH5TM for <tls@ietf.org>; Thu, 28 May 2026 15:21:48 +0300 (EEST)
Received: from LK-Perkele-VII2 (87-92-117-27.bb.dnainternet.fi [87.92.117.27]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: hliusvaa@dnamail.internal) by smtp.dnamail.fi (Postfix) with ESMTPSA id 4B3F14098F38 for <tls@ietf.org>; Thu, 28 May 2026 15:21:48 +0300 (EEST)
DKIM-Filter: OpenDKIM Filter v2.11.0 smtp.dnamail.fi 4B3F14098F38
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=welho.com; s=2025-03; t=1779970908; bh=p8Hw23pbYUxKBuwyw3kkfM+0wsjNebwQTZgK1Zznno4=; h=Date:From:To:Subject:References:In-Reply-To:From; b=nGVgLHjkolKYqNRfWt09E2e0i9a3XD6pFJCrOxN0pY4nYnj6N+PhlN+ggow4rS7iz 6j0V6PCOiE/mXELkfyVI64pgRAtUcTMctrf7JFwjLxQZuaLYzcciylsGd3GvHQKyE9 y4BA9AxIchOOETDTkbtmI0MNYWyFGhd/L/+5bKPSCTaBGMWAuZvkZ2pQLRMmG54Bjy cLMl6gYLrpYbg6oEis9OtL18jfoEvrZKIa06NBtUwu5nEhxYVO9jJc81HhU7p2d+V8 c1/A9t60++DNQdXrjdxP7g3+hTmRBCOMFYPpceWqorOqzpJlg1GacOUjbXSSczZ4eZ jrbsuG1xetLZg==
Date: Thu, 28 May 2026 15:21:47 +0300
From: Ilari Liusvaara <ilariliusvaara@welho.com>
To: TLS List <tls@ietf.org>
Message-ID: <ahgzW1SQNUS8OhUA@LK-Perkele-VII2.locald>
References: <20260519112813.1254795.qmail@cr.yp.to> <CAGgd1Ocy8f4HeQy-qWauAJAxizznXdXA53kWVp_FV1QUVGuxWw@mail.gmail.com> <5DFBF81F-4A98-4C5E-A060-580DC6960021@symbolic.software> <87v7c8lgt8.fsf@josefsson.org> <CACsn0cmaOdG4vCdeOVSxAPnJtPRH8rBJ3sfAY3o0f1fm-ouceg@mail.gmail.com> <ahddRzOIvQDXcvaG@ubby> <CACsn0cnStbBw8Szq+McPumjExnbL=3wmwESYEMWczJJZbJXRgw@mail.gmail.com> <ahdflj/Xy8VoOfH5@ubby> <CABcZeBO3hPa2PXNBzfBHLRAGdc3LzcpJGMQwo8f8ufwfhxy1Zw@mail.gmail.com> <87ldd4j7fm.fsf@josefsson.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
In-Reply-To: <87ldd4j7fm.fsf@josefsson.org>
Sender: ilariliusvaara@welho.com
Message-ID-Hash: M2GQ6LUUQPVWOOLFO35MGXI5JCEEWJTY
X-Message-ID-Hash: M2GQ6LUUQPVWOOLFO35MGXI5JCEEWJTY
X-MailFrom: ilariliusvaara@welho.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/Ik09bpLCz_fP_DkGGtvffR6090o>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
On Thu, May 28, 2026 at 09:54:05AM +0200, Simon Josefsson wrote: > Eric Rescorla <ekr@rtfm.com> writes: > > > The argument for hybrids in this context is that if if one has > > substantially higher confidence in the security of the traditional > > algorithm than the PQ one against classical attack, than it is safer > > to deploy hybrids. As as been discussed in detail, however, the threat > > model is different here because the attacker has to be able to break > > the vulnerable algorithm at the time of the connection (this is just a > > generalization of Watson's point), so the level of risk depends on (a) > > how rapidly you can disable the PQ algorithm if it's found to be > > vulnerable > > If there is no other widely deployed choice than pure ML-DSA that time > window will be long, and the level of risk high. I do not think the length of time window has material impact on the risk. If anything, I think that the time window growing would reduce the level of risk. I see three relevant risks: - Completely novel kind of attack against ML-DSA that destroys it. - Implementation flaw in signing that leaks the private key. - Implementation flaw in verification that allows forgery. The first was subject of intense vetting over a decade. And should that happen, we have a major problem regardless. And with regards to PQ algorithms, not all are the same. Even among "serious" problems (basically anything that is not "interesting"), there is great variability in confidence. The second and third can be mitigated by testing with test vectors. Preferably of adversarial kind that trigger, or miss triggering, all sorts of edge cases by narrow margin, or contain both vectors that pass and vectors that fail. The second kind only matters if ML-DSA is actually used. And unfortunately the third kind is not that severe comapred to kinds of vulnerabilities going around nowadays. > That's why we need several alternatives, including hybrid PQ signature > authentication. Alternatives are exactly what we do not want. Because those are harmful to interoperability, and destroying interoperability destroys security. Long-term keys makes signatures very sensitive to this kind of problem. > And if we have at least one hybrid specified, implemented and deployed, > I don't believe using non-hybrid variants is a good choice for a general > Internet-wide recommendation for the next ~10 years. We need to gain > confidence in ML-DSA and other new signature algorithms. I do not think it will be deployed. And with regards to gaining confidence, there is already substantial confidence on ML-DSA. -Ilari
- [TLS] Complaint to ADs and IESG regarding TLS WG … D. J. Bernstein
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Soatok Dreamseeker
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Muhammad Usama Sardar
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nadim Kobeissi
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nadim Kobeissi
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Deb Cooley
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nadim Kobeissi
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Simon Josefsson
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Watson Ladd
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nico Williams
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Watson Ladd
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nico Williams
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Watson Ladd
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Eric Rescorla
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Eric Rescorla
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nico Williams
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Martin Thomson
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Simon Josefsson
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Ilari Liusvaara
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Joseph Birr-Pixton
- [TLS] Re: Complaint to ADs and IESG regarding TLS… John Mattsson
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Tibor Jager
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Bas Westerbaan
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Daniel Apon
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Daniel Apon
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Tibor Jager
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Daniel Apon
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Simon Josefsson
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Salz, Rich
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nico Williams
- [TLS] Re: Complaint to ADs and IESG regarding TLS… IETF Chair
- [TLS] Re: Complaint to ADs and IESG regarding TLS… IETF Chair