[TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
"Kampanakis, Panos" <kpanos@amazon.com> Fri, 10 October 2025 14:43 UTC
Return-Path: <prvs=371f8d6b6=kpanos@amazon.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C337570BB5AA for <tls@mail2.ietf.org>; Fri, 10 Oct 2025 07:43:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=amazon.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5rLmLMifue02 for <tls@mail2.ietf.org>; Fri, 10 Oct 2025 07:43:38 -0700 (PDT)
Received: from pdx-out-009.esa.us-west-2.outbound.mail-perimeter.amazon.com (pdx-out-009.esa.us-west-2.outbound.mail-perimeter.amazon.com [35.155.198.111]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 445EA70BB550 for <tls@ietf.org>; Fri, 10 Oct 2025 07:43:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.com; i=@amazon.com; q=dns/txt; s=amazoncorp2; t=1760107409; x=1791643409; h=from:to:cc:date:message-id:references:in-reply-to: mime-version:subject; bh=eZnvEDcYPXcurcIRkoMjyWotYDojR1QDLDMBq4BXAjA=; b=aWHtBe/sE9vDWQJGv34IjhalUeeaKCR3GHVJ9xAgsDl7lp+uz35Ct06F dLsiDHD7b0gjDIoUZOv2bddNxpMhDu+1eViHlSngwt8nq0hLYWZQJ3RlB XygN5f6O+BTu7Kat53QzMeZcjwFbv9iUI0Cty+2xB28NzFz7BkOQnFqMX I4QN+YsbF5vKXf8PCP/24zpWXrv9aOpkmX/fba+ssqdufrE+VC2ncfBjn haM3CxToG06pTmIxG25YkCUI3Zu2fialJWisq3rjGB3ExHadlq2qRdVd2 +fFPPdaHwoWz1/sPc9lxAVZd5G/IypLSF5rHYvJjHwx6wWua4xT+0eLO/ g==;
X-CSE-ConnectionGUID: chrBqRdrQyawOkxY+/s2RQ==
X-CSE-MsgGUID: IDZI37lDQZqnjO+EbE6fgg==
X-IronPort-AV: E=Sophos;i="6.19,219,1754956800"; d="scan'208,217";a="4553240"
Thread-Topic: [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
Received: from ip-10-5-9-48.us-west-2.compute.internal (HELO smtpout.naws.us-west-2.prod.farcaster.email.amazon.dev) ([10.5.9.48]) by internal-pdx-out-009.esa.us-west-2.outbound.mail-perimeter.amazon.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 10 Oct 2025 14:43:26 +0000
Received: from EX19MTAUWC001.ant.amazon.com [10.0.38.20:6405] by smtpin.naws.us-west-2.prod.farcaster.email.amazon.dev [10.0.54.171:2525] with esmtp (Farcaster) id 5bd60cf2-0b22-400f-92f8-78b6a85944df; Fri, 10 Oct 2025 14:43:26 +0000 (UTC)
X-Farcaster-Flow-ID: 5bd60cf2-0b22-400f-92f8-78b6a85944df
Received: from EX19EXOUWB001.ant.amazon.com (10.250.64.229) by EX19MTAUWC001.ant.amazon.com (10.250.64.174) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20; Fri, 10 Oct 2025 14:43:26 +0000
Received: from EX19EXOUWC001.ant.amazon.com (10.250.64.135) by EX19EXOUWB001.ant.amazon.com (10.250.64.229) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20; Fri, 10 Oct 2025 14:43:25 +0000
Received: from CO1PR08CU001.outbound.protection.outlook.com (10.250.64.168) by EX19EXOUWC001.ant.amazon.com (10.250.64.135) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.20 via Frontend Transport; Fri, 10 Oct 2025 14:43:25 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=eb7VADdoLm9L8RPj+tbG9EPQTeCx/5U0JFMrakgfwNh/BrqEEhpD/wwhjdxMS3NRAwrA6HAZXY2cwJcxvZxlB9MkLucmspWrfhBdmjFtZZQsqzTnR9W+2G2J3Gxb89ks/juiPDKX0OmffqmgUcPx4rOTnaffDQhXUnMYWPkGIfPlltDJEav9BklI3xU8im/eUDBLjMfY0NRrcAm9zn+ryrmyEAIqV+m0ECesLcioQkNYrM+CSiqXYNP972Oou8z4D6iMRwcmDZW+bn7DqFWFGn5Ae2+Sc0/VsgdXx9gSCggesDSuqzVOOuTx8OvlkrdcppM8qq2BeLNU/JeLVDWESg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=eZnvEDcYPXcurcIRkoMjyWotYDojR1QDLDMBq4BXAjA=; b=hk+qUqMsrFbshNiPAqMhpJQTRRdE2UviRvSoLkHtfUstYm+eEfDBzAFfkjWetm4OD46wPg7Ivv2xgozlAFhdjMBL3MCJkxzY7DdW6SF4BX1UYw5VH109tHxrwWJ3s3ErUNJwKyO67/CcfN/00HQ7QH+v4xbL1GOYaTgRX/2/p9MfOUkwQARauJKCuuILSEWGm46z9N1PfdBhtqDPTWwx6ZYqWZ2vhQLcfr0RMOJBX21YZuq+IezukOxvudZvPcbZtxzPOCih4oV7tirK2iWUUAOpdK7c/2oEhav/c7TKLjuuy7w7w3Mysthr0pyg++ijbr37LcV/MZwZ+FWvI/t2IQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amazon.com; dmarc=pass action=none header.from=amazon.com; dkim=pass header.d=amazon.com; arc=none
Received: from DM5PR18MB2326.namprd18.prod.outlook.com (2603:10b6:4:b9::33) by BL1PPFAADA11AF7.namprd18.prod.outlook.com (2603:10b6:20f:fc04::db6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9182.16; Fri, 10 Oct 2025 14:43:24 +0000
Received: from DM5PR18MB2326.namprd18.prod.outlook.com ([fe80::6dd6:86fd:258:83be]) by DM5PR18MB2326.namprd18.prod.outlook.com ([fe80::6dd6:86fd:258:83be%4]) with mapi id 15.20.9182.015; Fri, 10 Oct 2025 14:43:24 +0000
From: "Kampanakis, Panos" <kpanos@amazon.com>
To: Watson Ladd <watsonbladd@gmail.com>, "D. J. Bernstein" <djb@cr.yp.to>
Thread-Index: AQHcOTZUpSlTa2ywf06ioDBFiNy9y7S6rNbwgAAdp4CAAFB/gIAAUlSAgAAHAcA=
Date: Fri, 10 Oct 2025 14:43:24 +0000
Message-ID: <DM5PR18MB2326019DC4CCD1F6B96A41E0ABEFA@DM5PR18MB2326.namprd18.prod.outlook.com>
References: <CAOgPGoA+c8kXDizwsvFG5tLz9+Kxk0HqiN1skKp5jMvvpxeu0Q@mail.gmail.com> <20251009160139.42473.qmail@cr.yp.to> <DM5PR18MB2326D93261B74BECF06061B4ABEFA@DM5PR18MB2326.namprd18.prod.outlook.com> <CACsn0c=ykksQG1P-gXYsL9v624E281a+4g0-qSjdky+SMtkKPQ@mail.gmail.com> <eb65d505-2375-4870-9df0-453666391770@app.fastmail.com> <CACsn0cmqFuzwQz4a_ZmpYbBqyPM8bAokjGeQtj4-xgq1tHSnDQ@mail.gmail.com>
In-Reply-To: <CACsn0cmqFuzwQz4a_ZmpYbBqyPM8bAokjGeQtj4-xgq1tHSnDQ@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=amazon.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM5PR18MB2326:EE_|BL1PPFAADA11AF7:EE_
x-ms-office365-filtering-correlation-id: f5a24a29-403d-45c2-095b-08de080b5db6
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|366016|1800799024|8096899003|13003099007|38070700021|7053199007;
x-microsoft-antispam-message-info: Z5JPOLEW9dgqWxLQ3ndewSa88rFH9nk22GQ94jvhf1zvWn811drYSS0qASAMFGrq+EIHnZDPsyvuIHFcA4s5gbxxObG1ho4VXh1gl21kj38PKGdQsDm2srszW8HnU1FfYdkAO/CIy3OhSznteC+odDVvxHilIQgXYIv4U/OiANvLhbMAn3a0V8tohG/SEN974Nv+PIomPh0X2TzPUorhJZrI9hdiaxP+c5EI8M/zYwP84KdDXqDtqW8RUcyQozXvISa+JZdzOXZojE+uc0kLlIoEjG1BAbYq+z4G4ZpeMYTH5beTlQpm+/To22TkfAzR3qVpdaFr8Kkg+3OP77UFUDDi+DuSZRcXHzoU+aLre3FAkLI0Yzq0A0u14B5F6/tg7ks1gWBAquqQKH5i75m8wDcbD18+3+91BJv1jbbphvLC2wxVidTKUFJdSfU1jtNjKdrSUOhx7MvmqLTk5glf2IKV9Xrls89nYMsCCP5ZxKB2FavFhgcHx/TntZb33d4hA/j9F3iCeWIsyARTNFbh6hdPzBXeSKO8Qi8ni6kESshO0gV/BMPepEB8AWZPtoAQq2bOfqbSh5HO3JbA3lrEMmqavQDUJOrRly4gGiga7X1pwdRxGeeUZZV3q+kG+/+1rgMlbNYD7ef9E5n7QAKo4o51lrMbCudD49JJJTYTnzrjQDOBUDSysVUd0UsqTy3Wo8U/+vZM39hKcJA1oRlyjwiFRZhkz259w+4BzCciOgin+kP7zuuMoE/G4pQG5qClvdIk7qEtoRHYYHL3i2cntCPit/fNHT8bbwikGvUCpZgqTIeWDk/Lgv8Xq/BJ7Ak37QzuIdQGbcuAkONKe8KDo5HMjk6wdBdlriII1Ax0C92skQUw1IqMCEsEoeUoulp4q5uBHqyKvESOlHaczBPXxFWnkgwi1MvI5u+PLhp9JRNC/vgUslbzEPzZ5bPL7mRLJGMVKqncWaJrRqocd2o1cXosaXMQvGrWCHktjWdY++7EYJPcLi7F4J0xzM4fWMS+ahJve5T6NbEqUdqDXSscy0UjOxjAVtY+AuUBPrMPwpuD+Y8zi6H9GNNJJOYfIHX2M49yjwRWa+19ZPvs4XeoL8Pmu1UgMBISADnAOsGMyHNMgQYkfpBK0o09QrmVzq4ffFFIX4TPL/JTxbB4HoQ90tF5jjvrL2Cdn5V91tmDGF1H1jrfJ+R0X9duLv+SQrWNmFuHCP0nfgtcusQUK8Nc22wLyRex1MWT5QruF6UBDIM50EtEbOOsFxfyu+4eerAmGAla8gM3xlA7bvxH+aX205ixUIxsDaqdJjsqYFh01jY+LqSQDucfHnE1NgTi79e7gP5zLcTkdVy8sZHexvcKDQ5Q7yQilPsqdZ57cfeBsBrPQrZMYLsDt+2CvbFctxrDdNiFhwb/T7LB81nqUnpbyXtirzwo2v2zoEHX/YrH50oz478+TX+6s58YIt3LHbp/w42BGZ8UIWte5M+6orCl8A==
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DM5PR18MB2326.namprd18.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(366016)(1800799024)(8096899003)(13003099007)(38070700021)(7053199007);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: JSXhBvweKw2er9o0UVZeqrEzB3hJLZKufVeXR6aOoMomXFkZgxvGUq6cu0ETI0URvm7NkR2RF4udnJziQ4RGW0h8QBgyRWIh0Sh4KI6SAotc7rFDF1aNsgaQ8F03ME8UjoL9kWuH5WuR52CfJpem+OtlwSGNcQw60riFhVj/COp1SWYnZrcYt295f8gTFn0AFh8m0ede8Uta3wCDNbIjPiFdCgxqIeUJHtLLNfPFccyKNK+4lQb+jCuijcWEbD1djIbr3TebDTKh/pe0Ln8mzcJBZAcTSe++86VeilbEcNCm8EZRdSNpnb3hfBBqmDByWd8rIxUrvHcADGY1ralaWb+Dt54Yq04JhX2qdpAiBQVOmuIT9ou0knuAH6OlHBvaL2BWE57SKenHRJAXvmjjYfrNc38IpSLjvLELsvjf5vaT5p03heGUoIi0IVRFf3nDmfRivybI56IQOPrr3LGCZ3w0Ht1zwWowy/1L1zpGv9zLs6Pcheq1qbvDanvNxXhJ0fbuT/Fy6Zv3lLx2KV8JPdKMtpf94JuKsr2rjJMe381DR5ozFGPRrxD6ovIWo6EPUfE9hhR7LHm+ZRK5jR3WJe5oZlRa8ItbCTzb5oQ/mjDj3fq6yahl3ygl2cQcRqr1uvYr53WlTy8KJy1ZDOFCUT6D6KbW3kMoE9MOoxfOsLI81NKuRZxb5YIefKxFdUEFtKbfzf1b+YZMklwwVFy4S9GlTqrBeUXKOv3CkUoZ+kyGkfieeRl1ttem6FMquykXDuEBNABL3yVCsZnbwG6iDc0CIvuIFmO+k7dzJfJdlZs+Q65dYkDykrfIwap+wE4TkDM3ttMDIkNUhPu1Zc3oNNFlh7DBF245qMB1mxL2tojtBa61y+85eMRuvx/A2Niw4BTsCxUYc0sHO68gAHbNaC73ZWooQzTok/wrLh2eBDZZmkwUHxcyCEyLVqAFt1aljmA1queFoIEN3PoMHIqIqQKq0tcc7p+mSf7S8whOFKekSWN+93X7SDBsU7Ua+RXKdl3zXFkNhIx1b2boH/gnFIPDNRMUpYndG2bzZb2XDPEhftDWQPkQK27PtPQR9VvuQL5KMHH/9InxORmsLz+hz+iKQ2HHmPWPq7C4wxuSjVISh0g15OwE7WPIwf5jNh9qku8tEt2+att2CbRrmlC6SRg7aK04YNtABU4FOTUXJFQjo5m/rtwXXSBG0bkMcNThAWfyFgTQHl6pgAYDFJT/n8dstcksZvmXoSY2wlINHGgmBo7qGvR26o+c9o22QSFp7viWYAH+FO0kRIud1cShGoM/OXbXfahTorNyc3flVj4oDowGoM2zSjWLfST4IpasYisMpe1U+7qcqhE2ESVLXXhsP9DnWkwMuCHNse/rqneShfzMOXpM5zLD/dv1YDzdhDcJHQs7Xfo86ilBNU13Y4c/LyKNUUe+5nTg6xoLQ8slic+zDN35LebDO25slzBYeroofSuGauNoneykkYFVkXnAJu8yu7y7MYb/LZKEYKH81Y1BigZhlwLl9wisEGjYVzMJJ9ju9iUOhGE4nxpMev/0naLcGGv+tHcSliKd+Uw=
Content-Type: multipart/alternative; boundary="_000_DM5PR18MB2326019DC4CCD1F6B96A41E0ABEFADM5PR18MB2326namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM5PR18MB2326.namprd18.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: f5a24a29-403d-45c2-095b-08de080b5db6
X-MS-Exchange-CrossTenant-originalarrivaltime: 10 Oct 2025 14:43:24.2739 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5280104a-472d-4538-9ccf-1e1d0efe8b1b
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: m1ZvkZnAxJTZaTCEfXLyplYRK4IqRafbpKRWij0t20EVYK5vWIzoiHM+qE3hrcyoGSoM9u7XP0RrBjPATCwKgw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL1PPFAADA11AF7
X-OriginatorOrg: amazon.com
Message-ID-Hash: XOX74VULUEY2IIPRADRXTNDVSAS3M2DF
X-Message-ID-Hash: XOX74VULUEY2IIPRADRXTNDVSAS3M2DF
X-MailFrom: prvs=371f8d6b6=kpanos@amazon.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: TLS List <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/LrAjUJLecqfbFKwsnyEdapsiRjw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Here is an idea: Write a “Deprecate ECDH with P256, P384 in IETF standards because they are insecure” draft like RFC9155<https://datatracker.ietf.org/doc/rfc9155/draft>. Until then, let’s standardize the already assigned codepoints. More codepoints can come in separate drafts. From: Watson Ladd <watsonbladd@gmail.com> Sent: Friday, October 10, 2025 10:12 AM To: Filippo Valsorda <filippo@ml.filippo.io> Cc: Kampanakis, Panos <kpanos@amazon.com>; D. J. Bernstein <djb@cr.yp.to>; TLS List <tls@ietf.org> Subject: RE: [EXTERNAL] [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3 CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe. On Fri, Oct 10, 2025, 2:19 AM Filippo Valsorda <filippo@ml.filippo.io<mailto:filippo@ml.filippo.io>> wrote: 2025-10-10 06:29 GMT+02:00 Watson Ladd <watsonbladd@gmail.com<mailto:watsonbladd@gmail.com>>: That's just objectively true. In 2014 I exploited a number of TLS implementations, ranging from browsers to embedded devices, exploiting incomplete formulas, failure to check y etc. All these problems don't happen with X25519, which is why it rapidly saw adoption. Do any of those attacks work against implementations that don't reuse ephemeral key shares (which thankfully are most of them now, to the point we've been discussing finally making it a MUST)? Yes. For instance one of the vulnerabilities was a DoS due to a division algorithm that couldn't handle zero. My understanding is that those attacks (and ~all the criteria in the "safecurves" webpage, last updated in 2017) are as irrelevant to authenticated ephemeral ECDH as the many cofactor attacks against Curve25519-based cryptosystems. There's also very poor performance of P384 and to a lesser degree P256. (With apologies for indirectly taking the bait on suspicious CIA techniques<https://web.archive.org/web/20250726032250/http:/svn.cacert.org/CAcert/CAcert_Inc/Board/oss/oss_sabotage.html>.) On Thu, Oct 9, 2025, 8:03 PM Kampanakis, Panos <kpanos=40amazon.com@dmarc.ietf.org<mailto:40amazon.com@dmarc.ietf.org>> wrote: P256 and P384 are risky choices now and the solution is for the draft to include only your curves with MLKEM768 or 1024? Come on man! -----Original Message----- From: D. J. Bernstein <djb@cr.yp.to<mailto:djb@cr.yp.to>> Sent: Thursday, October 9, 2025 12:02 PM To: tls@ietf.org<mailto:tls@ietf.org> Subject: [EXTERNAL] [TLS] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3 CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe. It's good from a security perspective to see the increasing deployment of post-quantum cryptography. The most widely deployed option in this draft, namely X25519MLKEM768, is reportedly supported by ~40% of clients and ~30% of the top 100K servers, so presumably it covers ~10% of TLS traffic already, which is a big step above 0%. Regarding the choice of ML-KEM, the _hope_ that ML-KEM will protect against quantum attacks shouldn't blind us to the _risk_ of ML-KEM being breakable. Many other post-quantum proposals have been publicly broken (see https://cr.yp.to/papers.html#qrcsp for a survey), including various proposals from experienced teams. Kyber/ML-KEM itself has seen quite a few vulnerabilities over the past 24 months, such as the following: * KyberSlash1 and KyberSlash2 (see https://kyberslash.cr.yp.to) prompted two rounds of security patches to the majority of ML-KEM implementations, including the reference code. * https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/hqbtIGFKIpU prompted another round of ML-KEM security patches. * https://eprint.iacr.org/2024/080 showed that NIST's claims of many bits of extra ML-KEM security from memory-access costs---see https://web.archive.org/web/20231219201240/https://csrc.nist.gov/csrc/media/Projects/post-quantum-cryptography/documents/faq/Kyber-512-FAQ.pdf<https://web.archive.org/web/20231219201240/https:/csrc.nist.gov/csrc/media/Projects/post-quantum-cryptography/documents/faq/Kyber-512-FAQ.pdf> ---are, asymptotically, completely wrong for 3-dimensional attack hardware and almost completely wrong for 2-dimensional attack hardware. * https://eprint.iacr.org/2024/739 showed that the same claims from NIST are, on real hardware, almost completely wrong. NIST has not withdrawn the claims but also has not disputed these papers. * https://link.springer.com/chapter/10.1007/978-3-032-01855-7_15 debunked previous claims that "dual attacks" don't work, and concluded that none of the ML-KEM parameter sets reach their claimed security levels. A Kyber team member has disputed this conclusion, writing "there remains a few bits to be gained by cryptanalysts before the security levels would be convincingly crossed", but in any case this falls far short of the security margin that NIST was claiming just two years ago.
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Paul Wouters
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Working Group Last Call for Post-quantum Hy… Joseph Salowey
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… David Adrian
- [TLS] Re: Working Group Last Call for Post-quantu… Loganaden Velvindron
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Deirdre Connolly
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Loganaden Velvindron
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… tirumal reddy
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Andrei Popov
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Thom Wiggers
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… David Benjamin
- [TLS] Re: [External⚠️] Re: Working Group Last Cal… Yaroslav Rosomakho
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Eric Rescorla
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: Working Group Last Call for Post-quantu… Martin Thomson
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: [External] Re: Working Group Last Call … D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Filippo Valsorda
- [TLS] Re: [External] Re: Working Group Last Call … Muhammad Usama Sardar
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: [External] Re: Working Group Last Call … John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Dennis Jackson
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Stephen Farrell
- [TLS] Re: Working Group Last Call for Post-quantu… Joseph Birr-Pixton
- [TLS] Re: Working Group Last Call for Post-quantu… Robert Relyea
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Sophie Schmieg
- [TLS] Re: Working Group Last Call for Post-quantu… Christopher Patton
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Muhammad Usama Sardar
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Appeal Response to Rob Sayre - was Re: Re: … Paul Wouters
- [TLS] Re: Appeal Response to Rob Sayre - was Re: … Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Peter Gutmann
- [TLS] Re: Working Group Last Call for Post-quantu… Yaakov Stein
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Robert Relyea
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Sophie Schmieg
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Joseph Salowey