[TLS] Re: FATT Chance: On the Robustness of Standalone and Hybrid ML-KEM Key Exchange in TLS 1.3

Deirdre Connolly <durumcrustulum@gmail.com> Fri, 05 June 2026 19:52 UTC

Return-Path: <neried7@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 66407FBEAD9E for <tls@mail2.ietf.org>; Fri, 5 Jun 2026 12:52:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1780689134; bh=UsfRdtqPiFsvIkmNJVXyf4xDxE7/UuVJPuEGH46pRls=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=pmKYWL+UChXJtFGiX17ljV4HMoH0WwyMeX3Hs/FZ3aU/0sZe3n7bR2Y242rCIFJlF QUow2NzRl0fuNRQPLi84aN4f5yLjrtgs9nDWUs79f0s0snbyN4Rf+ZclY6xyxZIttA lfdHW39OtgLYpqvlvFC9gTgPcybnLdvTILKQ3ufo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.848
X-Spam-Level:
X-Spam-Status: No, score=-0.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XGsCbIVSh2j5 for <tls@mail2.ietf.org>; Fri, 5 Jun 2026 12:52:14 -0700 (PDT)
Received: from mail-lj1-x236.google.com (mail-lj1-x236.google.com [IPv6:2a00:1450:4864:20::236]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 2ED90FBEAC86 for <tls@ietf.org>; Fri, 5 Jun 2026 12:51:26 -0700 (PDT)
Received: by mail-lj1-x236.google.com with SMTP id 38308e7fff4ca-3967725a77fso23821891fa.1 for <tls@ietf.org>; Fri, 05 Jun 2026 12:51:26 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1780689078; cv=none; d=google.com; s=arc-20240605; b=fLoGrlJUIzQidd+k7bjSc+ZcR4uYnU6bhbYN4p5zt+TBxxcXInEKteOds8HtQXvnI2 5EDXHoRgOd4u5toUgWCbNHFmREvEN7mOg+LZLt24YaCVbwMM0gwiapJML8bViwIGjAc+ h44diMF+iH4Ny5e1h4wC91KE6u/S09AcqE4zXnABkgaGedgPQYD45z6viqaQA8c1qNFc Hk14wGZ7NduqM7/q/7R5O50LFkhe/Qr22KMPFXTPfalAOq8HK5ArMVPGQlnYx87Ngk+e VfbwsAAyy53zZBfHyvUNm3bW4MyBYVZyV7dcp8NvDjYJ5Xqbq6y7jOdGlFBLaRQ5h1X5 le8w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=knAc5ml5z+GsKdNF7D4IXVjnKvdG71Sw/Pw2x5VomTY=; fh=qgCyQE05IpN1FUoexEVLgFHnhz+R4Ofb3T+OwmLltl4=; b=DmLLq4WQ0CBED1zPcsUOuH5YUHi1Rpn+pEO0s6cfzDaWk2kB5xT1o7kqYS5+odaTeb ti0J0dU5b5lhtiUem2QtQe+nWwe9ifQMu/aCT4kBdnfYRnOivW70AhvrQV4Tsli0kfYw DUr0qoUjY7XQziEwmf6s17I6JsFfCEngZ4HjPU5KxqeCWhwAxLQnLqgZLaXDGTaAMDM8 Y0mmKngKziLZqYxVS1fM3ekYnvx1v2o+EihnV8Vfnuz2ZVgutDDGH3Prp/HBdcGcGaFZ NDCpy0C1lYaEJyxUyShefzy3q2BsdfSrJpfv7g4F4v9pyyxHCgtDC+nbLZYGY5l7qaPk dJ8A==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780689078; x=1781293878; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=knAc5ml5z+GsKdNF7D4IXVjnKvdG71Sw/Pw2x5VomTY=; b=sZLwRAROzGCef1G4yAN5MjMv1w6OYhowYDeY1R9IPX6B9cJcH0CL4Of0cTiWJVKR1b L/lqX0Y3OjIHymKulFDilCvhFXnDW4KinJFcfGvyvKi6Na2DJ+h+XwZfJEHE7vN822R+ rhT7i2n13YI0jTUGJ1BlNoGIkELaJOEtT/Ygc5xE8TUdgTgaU6fQZswdmQHRtVBiEreb jQQSqAAlZiTLDCjLb2rd4ScT8aoFWaMf0kqgQu384+n7nyy75n3kd1tOOaol14yKXsdu Munhh3SuP4pVL0K1pDUYhDLrbbrNVvCVC1ejNvwn6hNkjsLvYAFJuB/Bkac2GSaxCO3x 1m1A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780689078; x=1781293878; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=knAc5ml5z+GsKdNF7D4IXVjnKvdG71Sw/Pw2x5VomTY=; b=iUuo9/w68v7v6bEFrqzEGpmfWAqRHdtE2HU3+/+3QGXH1/kQEps20KnCqaFWztckG9 NtGsTgmWonvOgW2lDOJxITPoMcbhn3ZLmq33HK8gWynOgLcZLZy6tpID4tlvbznxZVnd 99e2m8tgrtCcb9L281Y3jMTJv3vcmIRzq3WTbmwFHzc80KcCX15MeW424dhDJdC2I0zD o/sASzc77260Zh5k8VoLpwg52xstH/GMDaSNzRRhaGndUl9ZXcL6FiNDENOhxQzjEfNE LIsK7MpUKk2cDRgNs2/SIi+L4EIv4iICQdElIhYw02OWhOxAW33T9EjjrEyHHhLkQGMD CSwg==
X-Forwarded-Encrypted: i=1; AFNElJ9mTDmX0Dx8OdSwjprNSiGAP6GLrmGxiMYmfc78lKLsxl/Ce//8sUAtf9FCt9ZYBJ8NLWw=@ietf.org
X-Gm-Message-State: AOJu0Yw8pSzzuWQSyr7yMNoLggXnlchJ3TnrqL8FCnVB3kO9fH8UzuQx C4dyWMArLbADuAUq/z26ALfcR6M26/u+AVQR7rVfekzg0GgTcEL8Fz9lhdHtRVkCUjv93+oolt/ 7NqiVPpJNtVuHacturc+XBGYxVeUNYz8lqhQjENA=
X-Gm-Gg: Acq92OEBtzN4LPac1j1R6U/Lr+anRnWvy3Tcs1nBN+3EQM+m6QlYQK9rPPEEsHU3GJA QlrONKmt/1hh63VJLs9phHuAbfTNOzYNXvIK2q8BHNBadwmiWgIQnraWwWtcWTxjUIMYnGhGAuA qov4VWZeQlsufRKb1B5BILbu6wUaK5NlBJiEh6DES7MAg4xYCpa8IFC9MDuAkTcYV2cbyL0IFnn 1Wi1nvTnrPIEUwB1mAPD3u7UmDvR3zpDPwYh3x/4gv9gna/gQbbphgvcj0AepkZsI3+Hk+tRIAu qza2PMV+ozb62jEd5VT3KSqYCFo0PQ==
X-Received: by 2002:a2e:ad12:0:b0:396:94fd:35dd with SMTP id 38308e7fff4ca-396d09ebcc9mr15321871fa.29.1780689078068; Fri, 05 Jun 2026 12:51:18 -0700 (PDT)
MIME-Version: 1.0
References: <E3248C6C-F41D-4697-B484-5DD3B3F03893@symbolic.software> <cec4e220-0842-486d-9c69-ddaf37260da4@tu-dresden.de> <MN2PR17MB40310B7FDC1875D16334B680CD102@MN2PR17MB4031.namprd17.prod.outlook.com> <154E6BD1-8F60-4E84-930D-751A812840C8@joseon.com> <MN2PR17MB40317BA388E060026831EBA7CD112@MN2PR17MB4031.namprd17.prod.outlook.com>
In-Reply-To: <MN2PR17MB40317BA388E060026831EBA7CD112@MN2PR17MB4031.namprd17.prod.outlook.com>
From: Deirdre Connolly <durumcrustulum@gmail.com>
Date: Fri, 05 Jun 2026 15:51:05 -0400
X-Gm-Features: AVVi8Cf5sF77z25i4sP9qkQIa7sDEkG5aWlYVoPH6o_6GmP1lVS0bKGC5nD3sNM
Message-ID: <CAFR824xH_fi1v1m5++noZ1J6wg0zvrTF+KwF+aobun-r=QvWjg@mail.gmail.com>
To: "Salz, Rich" <rsalz=40akamai.com@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="000000000000f42a90065386fb22"
Message-ID-Hash: CPNHXAY6OPICYJBTNMIQQ723V62FLYGT
X-Message-ID-Hash: CPNHXAY6OPICYJBTNMIQQ723V62FLYGT
X-MailFrom: neried7@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Andrew Lee <andrew@joseon.com>, "TLS@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: FATT Chance: On the Robustness of Standalone and Hybrid ML-KEM Key Exchange in TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/JB_LG_DQ9BvJLnYj9xIl82lm6Zo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Correct, all versions of draft-ietf-tls-mlkem including before adoption
have had Recommended=N for all parameter sets

On Fri, Jun 5, 2026, 3:34 PM Salz, Rich <rsalz=40akamai.com@dmarc.ietf.org>
wrote:

>
>    - This happened after a significant amount of time and was
>    deliberately steered toward the opposite of said result
>
>
> My recollection and view is the exact opposite. ML-KEM key exchange was
> *never*​ going to be RECOMMENDED=Y.  The system worked.  The “outside
> interference” just made it more complicated and caused a great deal of bad
> blood and distrust.
>
>
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>