[TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt> (ML-KEM Post-Quantum Key Agreement for TLS 1.3) to Informational RFC
David Benjamin <davidben@chromium.org> Tue, 11 August 2026 21:47 UTC
Return-Path: <davidben@google.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 79E3A1281D9BF for <tls@mail2.ietf.org>; Tue, 11 Aug 2026 14:47:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786484834; bh=VQTI4tTvbln5Gqqqo2ZjIhgRM1b2FP8TgGrR2B9wNMo=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=kLPJcY17ptmMGZM4UACO+G3FfD4DDCefyjtZ5hThXX/SBVqkr6QaVibt21VCrFHuw msnU29IB98HFK0wZuZlwyYjmVchLmMYRSF+Bm9iJ8T8/ZG2+FhXICXklLwVASYQ8w9 wIUmlJm0VEUzacRysjORRUQ8zNuXgh8MTtV5OuOg=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -9.489
X-Spam-Level:
X-Spam-Status: No, score=-9.489 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=chromium.org
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id phP2GWXHh2S1 for <tls@mail2.ietf.org>; Tue, 11 Aug 2026 14:47:13 -0700 (PDT)
Received: from mail-ed1-x535.google.com (mail-ed1-x535.google.com [IPv6:2a00:1450:4864:20::535]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id ECAB51281D9B2 for <tls@ietf.org>; Tue, 11 Aug 2026 14:47:13 -0700 (PDT)
Received: by mail-ed1-x535.google.com with SMTP id 4fb4d7f45d1cf-6a18e24ad25so449107a12.1 for <tls@ietf.org>; Tue, 11 Aug 2026 14:47:13 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786484833; cv=none; d=google.com; s=arc-20260327; b=ssElyt3paoFC0LHjfsLZ31pZ24A27/5rch8SG/sRiy1TY2lrE1EhuwpE+HDjX0kMyr iOTeEE5BiJtv6N8M52M9DLQtZXuB9cJSCZAkRyMo2y4sAK6UIGut4QBLFNTxEnaPZpDh lmPBMDgePhTbzs61lxn1xEZbZ7etMigvsEfsA4KJcWjCeCcmaPjivYZCQov/CDZyJ3TF pgfEa1lYkstxkKQO2s+hvrG8ZbHXjuAzBRKOCmiAfeBXrUNy51sl76/Nyr69TFrJGfuP w8gBdDQaLa29y8k2WMqoRaHNGv0VgMg80zbjKnf443P8JgAsNKCTdXEncR9W5rMmLmDV DMNQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=VQTI4tTvbln5Gqqqo2ZjIhgRM1b2FP8TgGrR2B9wNMo=; fh=+FSue5FF8BvP3GQDRX+h21xG0km89/HHS3dj8M3n7mc=; b=ZJXcgVFIBQDFKNKkdcMqimYwRw6lLRnUYsygoZ+Gw/kI88PQHBKNPNahcm4ZGmccIX yvROEfiC9y/x2wUY2kswrMl/9RkFjZFtSn0CQWkbY0rjxATQu0w/6HB5aIAlsOPEhNlg RFbzfds5wWgizk/T3rALEBQq0pVQdZ4R3Hc0S4mn+ucnETLjQDLrr+xxESamnnUp52qv 5ixDQqS3gfNlxiboJMuTMa4ZrU6C0eworvWnxpCZcmz5MOq9YHVP7Rf+DGcKkq6qXg+P iRxFl8AqV9dD1fREJB8d0RNR4G4rVRIJ0yr7iJE9Yx7APSX+VGOBmeCqYL4EAzGbgU+O RFhA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1786484833; x=1787089633; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=VQTI4tTvbln5Gqqqo2ZjIhgRM1b2FP8TgGrR2B9wNMo=; b=jN/XpSrzChhaNTGtGHDQkEggbqz9jMPRLzesEMqS1Fc9nJPn6jg3tSJ0ByHflaND5s TrZWNBiaJuqwkYclZ43EZQNWfL68pwBJmJzpqOt6LlfOJ6O4CveiwK97fUu8fdD45DV0 sddBtSFNqe+rGRtcJboqxd/blsbAuEXUt1fvw=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786484833; x=1787089633; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=VQTI4tTvbln5Gqqqo2ZjIhgRM1b2FP8TgGrR2B9wNMo=; b=KtND0zq1HpNTKa6dlBI1/l12TT8Pz5P+7Bxxecs1laOF+M0FVf7Ze55j4ju61vcL1P l1yYC71DcEg2fuwrH4wnNhAC+YlsAqaVTnfafCrJSgWOWZEhPQs87dLQ1lcwVJWKriGH c/wAH8JyPv76yGg/MeBwYYg5o7+Mkth1Y/UQg1bnWXu8Za5luEdpKiK9Hh5uuMjxgnTp UN/zSm0MAG8T1nS4PVRoN3iReOZ9aDdPMA+q+jrjlm9a27j8PR4tUCTK7a3iJcQmbgAu +pbJ6GjpOG/jCSK0g41hjPw9QY9TKS7cVbvXyiay1VgunZcnmSGLrV2Q5SvAk5X0hnUT GrYQ==
X-Forwarded-Encrypted: i=1; AHgh+RoZcX4lbBOq+4aUzxipMEEZhd4oypOMQxKZDMVKhTLaelAgVj3mJGBBiZiAf2e+PsLt8Do=@ietf.org
X-Gm-Message-State: AOJu0YycwSyWDrDmP18IOacC3frVa3wLA7XYMWF6foQJxXhDozWXoRHT IEeGnuTC4v95X2Dqiwi5m9Kbq6V/Fux18k2bf59o/soA8ZjIwc5m+dUWLga+d0JDiYHYhhztWhr mlOZD5sbDKODKrN2ruxhyQY4P7WlEoMzpIinwSCkntq5ODms6zXdhOQtxtg==
X-Gm-Gg: AR+sD115tCMpT1CuP1PZmFRjjX14Aq5mJkdLe9JYXWDGHxhXIiTLpONO/xOTjDMkbtj OMPpPw+CCTRZ2a71odvU5izoQucRkVIH4BpxawoM4H9wu2NA3W4Sz4eXDCPYvFggLyGrgO/ySlQ 8tgf+JfccCWX2c9fiL5muejDS8iLGF45Dw9m7qeNgCvAM/zUdC8+5hvyX9Xy15Dj082Wdvx/7yx B2M0kaJRKq4hXAGVnGcXlf4iv8y9eLGxTBSnGk1fDHVdEMJL2/W3EEHe+2vaQcCyZ36fgaDh5aU ECfoxINNaqfyDw8aMQ9FCwjYwPHfn6aJ0mjOY0ZhN1alkofRNZPUPrQxjT/g0X0nBXwXQeeKRKi 8HYy1vftxEAaXLHLU9S6keQP+JtIFrg==
X-Received: by 2002:a05:6402:c4e:b0:69e:8ad:5162 with SMTP id 4fb4d7f45d1cf-6a36447c0c6mr3690199a12.1.1786484832350; Tue, 11 Aug 2026 14:47:12 -0700 (PDT)
MIME-Version: 1.0
References: <20260811105051.2792930.qmail@cr.yp.to> <996f4ae94583837bf48195eb8293740b90a27c75.camel@fehcom.de>
In-Reply-To: <996f4ae94583837bf48195eb8293740b90a27c75.camel@fehcom.de>
From: David Benjamin <davidben@chromium.org>
Date: Tue, 11 Aug 2026 17:46:55 -0400
X-Gm-Features: AUfX_my_vS8KFmMrauW32SaRevS9ivfhjefxXCCsmirhy78ZrbvSG3YOuXn-Vqs
Message-ID: <CAF8qwaCnVmBg6AraXRLE36oT6S7RaEhJfzBgV=O4Q0wp7nP0aw@mail.gmail.com>
To: Erwin Hoffmann <feh@fehcom.de>
Content-Type: multipart/alternative; boundary="000000000000d572a20658cc69e9"
Message-ID-Hash: RG6IAR3YXHCUTFRWYEMTLEAMZK5QK4ZC
X-Message-ID-Hash: RG6IAR3YXHCUTFRWYEMTLEAMZK5QK4ZC
X-MailFrom: davidben@google.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: last-call@ietf.org, tls@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt> (ML-KEM Post-Quantum Key Agreement for TLS 1.3) to Informational RFC
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/LaZwmoGaUxxGQXKvfa58mPg77y0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Just answering the one misconception about TLS 1.3 in here: On Tue, Aug 11, 2026 at 5:33 PM Erwin Hoffmann <feh@fehcom.de> wrote: > 4. The way the random number is used in ML-KEM, does IMHO not conform > to this basic assumption: It is fed directly (not taking the > transcript-hashes into account) to generate the Master Secret [2]. > Correct me, if I'm wrong. > > 5. Thus, at the bottom-line, the Master Secret depends solely of the > quality of the PRNG. As explained in [1], its Algorithmic Information > Content (AIC) is preserved given the ML-KEM handshake. > This is a clear violation of risk-minimization because of disclosing > its origin. Additional hashing would involve some additional > computational cycles, of course. > While it is narrowly true that the TLS 1.3 "master secret" (called the "main secret" in RFC 9846) does not incorporate the transcript, this is a red herring. While it shares a name with a TLS 1.2 concept, they are not used in the same way. The "master secret" in TLS 1.2 is the primary output of the TLS 1.2 handshake. It is the resumption secret in a TLS 1.2 session, and used to derive the TLS 1.2 record keys. That is not how TLS 1.3 works. In TLS 1.3, this value is *not* the output of the handshake. (Our implementation does not retain it after the handshake at all!) The outputs of the handshake are not the HKDF-Extract left spine of the key schedule, but the Derived-Secret values on the right. Each of those incorporates the transcript. You'll see different prefixes in the diagram, but this is simply because they're computed at different times. https://www.rfc-editor.org/rfc/rfc9846.html#section-7.1-13 So, no, the TLS 1.3 handshake thoroughly uses the transcript hashes in all of its outputs, whether the key agreement is ML-KEM or something else. All this was part of very thorough analysis that the WG did when TLS 1.3 was designed. David
- [TLS] Last Call: <draft-ietf-tls-mlkem-09.txt> (M… The IESG
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… Russ Housley
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… Bellebaum, Thomas
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… Nowak, Adrian
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… D. J. Bernstein
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… Erwin Hoffmann
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… David Benjamin
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… Erwin Hoffmann
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… David Benjamin
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… Sophie Schmieg
- [TLS] Re: [Last-Call] Re: Re: Last Call: <draft-i… Salz, Rich
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… D. J. Bernstein
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… D. J. Bernstein
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… D. J. Bernstein
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… D. J. Bernstein
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… D. J. Bernstein
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… Nadim Kobeissi
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… Nadim Kobeissi
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… Christian Huitema
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… Rob Sayre
- [TLS] Re: Last Call: <draft-ietf-tls-mlkem-09.txt… D. J. Bernstein