[TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa

Tibor Jager <jager@uni-wuppertal.de> Sat, 30 May 2026 19:53 UTC

Return-Path: <jager@uni-wuppertal.de>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 37444F81C24A for <tls@mail2.ietf.org>; Sat, 30 May 2026 12:53:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1780170799; bh=CVWx/rOuqXaRNngSPlICS+cCF/1W3QHDthuOV0N1Kys=; h=Date:Subject:To:References:From:In-Reply-To; b=u6ftzwTzVHYk4Dt+dhng87Hv+b8rYkS3fvCaecXcUALqWpumlVMnhYOg62j2b1GPJ jFoa7mXsiI7c6onCooFOHSXH6HbfFLD5VpvArg7EzdekV089dHwB+Ly93NaOn9NKno zhIl8mrjjy+ZGoyM91KFOXGPpRrFtkslQJEIwDmQ=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=uni-wuppertal.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id g6XROFPRRwIz for <tls@mail2.ietf.org>; Sat, 30 May 2026 12:53:17 -0700 (PDT)
Received: from smtpout3.uni-wuppertal.de (smtpout3.uni-wuppertal.de [IPv6:2001:638:50a:64::73]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BE41FF81C211 for <tls@ietf.org>; Sat, 30 May 2026 12:53:12 -0700 (PDT)
Received: from smtpout-intern.uni-wuppertal.de (smtpout-intern.uni-wuppertal.de [132.195.64.33]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519MLKEM768 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by smtpout3.uni-wuppertal.de (Postfix) with ESMTPS id 128FC17DC7E for <tls@ietf.org>; Sat, 30 May 2026 21:53:05 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=uni-wuppertal.de; s=mail; t=1780170785; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=CVWx/rOuqXaRNngSPlICS+cCF/1W3QHDthuOV0N1Kys=; b=hJ7tYr/A2nn6ByYHlJDBaDR1SSH2S4DZdwm9mOu7dV68jDSOY/LVz36+jNJe5Rm37gOfQn fk+q03uLJL8jjLFuIs/NKHIvB5iF/+bQWKlvWC4UPeEH84my21zQqyP8tq4ytZ+Ef4De4W UF9dHcqPu11BkrJDg21ILAUaTn5JcxA=
Received: from mail.uni-wuppertal.de (mail.uni-wuppertal.de [IPv6:2001:638:50a:64::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by smtpout-intern.uni-wuppertal.de (Postfix) with ESMTPS id F33C79F26A; Sat, 30 May 2026 21:53:04 +0200 (CEST)
Received: from [IPV6:2001:9e8:cbfe:9900:21db:c42e:3646:e6f4] (unknown [IPv6:2001:9e8:cbfe:9900:21db:c42e:3646:e6f4]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail.uni-wuppertal.de (Postfix) with ESMTPSA id B932111FD; Sat, 30 May 2026 21:53:04 +0200 (CEST)
Message-ID: <85e8b5d6-3ad2-4722-bc8c-32b48b83b3ce@uni-wuppertal.de>
Date: Sat, 30 May 2026 21:53:04 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: John Mattsson <john.mattsson@ericsson.com>, tls@ietf.org
References: <20260519112813.1254795.qmail@cr.yp.to> <CAGgd1Ocy8f4HeQy-qWauAJAxizznXdXA53kWVp_FV1QUVGuxWw@mail.gmail.com> <5DFBF81F-4A98-4C5E-A060-580DC6960021@symbolic.software> <87v7c8lgt8.fsf@josefsson.org> <CACsn0cmaOdG4vCdeOVSxAPnJtPRH8rBJ3sfAY3o0f1fm-ouceg@mail.gmail.com> <ahddRzOIvQDXcvaG@ubby> <CACsn0cnStbBw8Szq+McPumjExnbL=3wmwESYEMWczJJZbJXRgw@mail.gmail.com> <ahdflj/Xy8VoOfH5@ubby> <CABcZeBO3hPa2PXNBzfBHLRAGdc3LzcpJGMQwo8f8ufwfhxy1Zw@mail.gmail.com> <87ldd4j7fm.fsf@josefsson.org> <ahgzW1SQNUS8OhUA@LK-Perkele-VII2.locald> <CACaGApmvARUhMiMegHp+Q0O5KuYwW66qOYxQcV9DdKRfHu24EQ@mail.gmail.com> <AS4PR07MB8825B332ED2BFEA91BED403589172@AS4PR07MB8825.eurprd07.prod.outlook.com>
From: Tibor Jager <jager@uni-wuppertal.de>
Content-Language: en-US, de-DE
In-Reply-To: <AS4PR07MB8825B332ED2BFEA91BED403589172@AS4PR07MB8825.eurprd07.prod.outlook.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms070705070205000300060205"
X-Rspamd-Pre-Result: action=no action; module=multimap; Matched map: WHITELIST_SENDER_DOMAIN
X-Spamd-Result: default: False [-20.20 / 100.00]; WHITELIST_SENDER_DOMAIN(-20.00)[uni-wuppertal.de]; MIME_GOOD(-0.20)[multipart/signed,text/plain]; URIBL_BLOCKED(0.00)[smtpout-intern.uni-wuppertal.de:rdns,smtpout-intern.uni-wuppertal.de:helo]; MIME_TRACE(0.00)[0:+,1:+,2:~]; DKIM_SIGNED(0.00)[uni-wuppertal.de:s=mail]; ARC_NA(0.00)[]; FUZZY_RATELIMITED(0.00)[rspamd.com]; LOCAL_OUTBOUND(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; FROM_HAS_DN(0.00)[]
Message-ID-Hash: SRG3G5LDNUEVXB3QJ5YFXBIDESQBQBAJ
X-Message-ID-Hash: SRG3G5LDNUEVXB3QJ5YFXBIDESQBQBAJ
X-MailFrom: jager@uni-wuppertal.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/NnGrdavTY6KGTVQo46xaPbSHQzw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>


On 30.05.26 14:11, John Mattsson wrote:
> 
> - Most experts have a high degree of confidence in hash-based and 
> lattice-based signatures. This includes US NIST, CNSA 2.0, European 
> crypto agencies, as well as cryptographers in academia and industry, 
> such as Sophie Schmieg [2].

This suggests a consensus in academia that, as far as I can tell, does 
not exist.

Regarding “most experts”: the authors themselves (!) of Dilithium/ML-DSA 
recommend hybrid deployment. On their website they write (see 
https://pq-crystals.org/dilithium/index.shtml)

"For users who are interested in using Dilithium, we recommend the 
following: [...] Use Dilithium in a so-called hybrid mode in combination 
with an established "pre-quantum" signature scheme."


Similarly, for Kyber/ML-KEM (see 
https://pq-crystals.org/kyber/index.shtml) they write:

"For users who are interested in using Kyber, we recommend the 
following: [...] Use Kyber in a so-called hybrid mode in combination 
with established "pre-quantum" security; for example in combination with 
elliptic-curve Diffie-Hellman.


This statement might of course be outdated, but I recently asked one of 
the members of the CRYSTALS team whether this is still his view, and the 
response was: "Yes, of course."


In my view, the concern is not with lattice-based cryptography as a 
paradigm, nor with the algorithms. Also, not with backdoors. Rather, it 
is with the underlying hardness assumptions and, in particular, the 
concrete parameter choices. At present, these appear fine. However, 
assuming that this assessment is unlikely to change seems optimistic.


 > I am very unconvinced by people who criticize ML-DSA while
 > not applying the same scrutiny to RSA, ECDSA, and EdDSA. The criticism
 > of ML-DSA and IETF often applies double standards that don't survive
 > scrutiny.


The above comparison is not entirely apt. 30-40 years ago, there were 
fewer alternatives available, computational resources were much more 
limited, and hybrid deployment was generally not a practical option. By 
the time computational costs had decreased, RSA and 
discrete-logarithm-based systems had already accumulated decades of 
scrutiny and practical experience.

More importantly, in my perspective, advocating hybrids is neither a 
criticism of ML-DSA, nor an application of double standards. But it is a 
matter of risk management. We are considering introducing algorithms 
based on comparatively new hardness assumptions into the most important 
cryptographic protocol on the Internet. There is nothing wrong with 
optimism, but in this context one may also argue that a more cautious 
approach is warranted. Better safe than sorry.