[TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
"Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu> Mon, 13 October 2025 16:10 UTC
Return-Path: <prvs=4381760925=uri@ll.mit.edu>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6B95F72893B0 for <tls@mail2.ietf.org>; Mon, 13 Oct 2025 09:10:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.297
X-Spam-Level:
X-Spam-Status: No, score=-4.297 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=ll.mit.edu
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yD2k-hKqigSr for <tls@mail2.ietf.org>; Mon, 13 Oct 2025 09:10:14 -0700 (PDT)
Received: from MX2.LL.MIT.EDU (mx2.ll.mit.edu [129.55.12.51]) by mail2.ietf.org (Postfix) with ESMTP id E555872893A6 for <tls@ietf.org>; Mon, 13 Oct 2025 09:10:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ll.mit.edu; h=cc : content-type : date : from : in-reply-to : message-id : mime-version : references : subject : to; s=dkim1; bh=pzOBL52IvWml9PPNcsYeftR3QzsnovPLpQW3MaBUvgg=; b=Ibwu+43MhM4ZPZKAYpAoMpokDJnI+JBijYsSI5l3lFRYW/UXQHqPL7lz1If5Vsiy5HM9 PHHVumyyE/lXZhaweCXrXVZE/+uA74Srk2CT4Vb6HdNJMCQZK2G99tSe4EnPdzWp85Oz knBnGHl68TgefWY3EbYUkH1iITUwi94VJkpHC55Q6c9+mthYpjwEBSoWGlkmCwmrnRCP nTpxNg04hkn3EDpYSPMhrgNID0c7mvq1RXNczrWyl3jT3wC+fnX47C84GTnhbdLHXnrm tveWiQ14P5dlML7tMygeCzxXm2p3340vJJCYenZGEHMAJ3dxoTuc3Ovg0zZQXKo1VjMO Uw==
Received: from LLEX2019-02.mitll.ad.local (llex2019-02.llan.ll.mit.edu [172.25.4.98]) by MX2.LL.MIT.EDU (8.18.1.2/8.18.1.2) with ESMTPS id 59DGAAqt028184 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=FAIL); Mon, 13 Oct 2025 12:10:10 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector5401; d=microsoft.com; cv=none; b=p6YuSRpvgw3ThGZym8G2aro6LPMNGRazS4VWc8qMOHa6NcdipI2vEC3AG/YEyX6+Xg1qwTaPVzOQQp8fADnkFGFHGSb32PK/USx1gIXx8R9wkaCjuwYTcfITzEQwsUDnW1B6TgTUsvrsq7bhXPDM92TSUdcKCvmp/haa5xQU1uHrbYNgv6GA3oGBB2/HrO6Pat5XtE/1QCC0xnKdjzq93hUhW9KOVT2cCoNcgr6PE9m6UzKndf5E7WZM6bi3OTRq5FcxpmE1S8mc3hm0FRj6aJyAmmQtVq6en4N9UXkmYKu6ugaEkaLIMqjTzHXh/cTALXndb74hyOMccaBsqC53PQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector5401; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=6FMlUqYBku532Q/PbS34hPQUI4HnuwfMWrD9t8gUaJM=; b=pdNaICV293q3wc8AF7u3tyXsHuO5nq3DfauM4SsOKWvjjRkm5wq2s+5c7s0RkwfAOaJ5CVP5X1yZxpkCSsVGeDbLrZUnQveUb2ZquxIHPBWJHTyAj60Fknlb6Yai4ODtnJP4JygZctjOE4295dSRyl9usZQXU1L9B8FrIL27Pb0hKL1uSddawpvX2bBAEBVx95k5vxN6ahR9/RQd9LyZ9o7bGNqpJ5rvJICqqF/0GqIAT8UpXG0XzF40SBptfyFHtlpZk4TPs+fL+XlfXkPaN0bZLlJ/2HjF332ro3gl6CNPLvAPYQNSOJwUcw7qxcodqxDHZroY96oZrCN5BnkpZA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ll.mit.edu; dmarc=pass action=none header.from=ll.mit.edu; dkim=pass header.d=ll.mit.edu; arc=none
From: "Blumenthal, Uri - 0553 - MITLL" <uri@ll.mit.edu>
To: "Bellebaum, Thomas" <thomas.bellebaum@aisec.fraunhofer.de>, "durumcrustulum@gmail.com" <durumcrustulum@gmail.com>
Thread-Topic: [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
Thread-Index: AQHcPDBON3AXi51gAkalb4T455hhYLTAOJVL
Date: Mon, 13 Oct 2025 16:09:47 +0000
Message-ID: <BN0P110MB1419FADCDDF236E0481D365590EAA@BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM>
References: <CAFR824wG_3h3P0cM_oe4sAA2T9si2KteZRvi3UbzC7gs6hV7hQ@mail.gmail.com> <551EC460-8C2F-4FB5-B95C-D11DCD84BB61@ll.mit.edu> <3f2a02b66e77b648e008962493a956568e4e22a7.camel@aisec.fraunhofer.de>
In-Reply-To: <3f2a02b66e77b648e008962493a956568e4e22a7.camel@aisec.fraunhofer.de>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-ms-reactions: allow
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BN0P110MB1419:EE_|SA1P110MB1535:EE_
x-ms-office365-filtering-correlation-id: 5c3120d4-453b-4b9e-78df-08de0a72f928
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;ARA:13230040|366016|1800799024|38070700021|8096899003|4053099003;
x-microsoft-antispam-message-info: 6kElOaTjm1dyCRr62kO96lANmlC+vJHn/e0xFc65jN4pcro3SbS7F+320TzI7E2wXwYKohMX7lWo7izbu9fTQd3AYqgBrxlDN4aqAjo7vRG8AZ00Nv7DROvKK0u9oS03B7fvItWaUK+UDMHzcy6q83+wLdVWwfguHkT6XlsHCw/THupA3hk0mZrN6YghM0RuLGXpTQIRaWT0cvBEA41dlGahoqls0Vx8bMVqaxI0zeLpyMuQNICfd6EnMS2x9fjQI+zbYlrE6NhxYNcW54JkCWANXRJ1quxSUAZG+osUl/AQ+RQPUAE1a3vjOpfl2we1TueiYVJk689gk0g3AhoRhuIv74hqaJI8Met6HP7UVKgMpI9zdc4dhomQKBnNLwRkGoTau/MdgGJmKGniD2nRVj9Nq+pNosLrFc+kme6hvIgDgF12V5HoB08r15LVBgoRxrjvWcV2wCEThKdxG6a7sVA0CeO7hZdAE/YH8tkMbFU+cm6+PpbhA+wSgbCS3HJh/3XGrjwQovuY4mOPSDFqqk5z52D4YoWwn9FUTsbiz4PdE6Y5zW87piy2g8U/3OdHjcFEkXlPESsr+olfYi1urJQc/FwXguTbSLAUhWLZ/gxfcQkGN8PCCQnFbVUkndX8HPnUzWRDZfq+gYSnhgYA2iiAbc3XFEjXvqxCyimC0qcP0O7xuuxZQVV76LPJmWYQa/z76zz6gRHUIlD+wFlGtOxrC1tFblg4SRuZkRg+uZk2a4dM/2uk9cAXUqC+v8ehnHsMLphj92CdTl2D/8lOCQpJjZTpn3KheDt9oVO9FuoDuhQCYZLuywqaoq1pwJRKrete7kdSHYFqaJIb84n/hn3hgGOWZpU459YTHN3mKJAVKPgFiVjJND/Qv7v28LUrTo75NVAAsj7DP6yqZKznaTUQHmHjDpjhZi1sUbpUYvwG6JUx8e5oxIrzS7YsbfqPZ+/IYxEy8ZpXbLfmpJFTONLQSOlbldCvjUgjfYbV8rK2tzhlQehksGswysVtSD/uU4vqslk6LC7Fa3gUQG/0wC0aksZG7DZsMa06vEb3KLxUo644XHXjJPfCoIplmFLdSePUTGV5WFNJwALUgKKjpl3fvs9cLMwT9NxA76OtBh1oMY8tYqgZhwH0NlM+d42bVdJEXYqkoRBmdASVBOM82Y7KzZ7HFXFbsB/x/ijgkkoCx/I63ZxAq74EDi/rGVpDDFU8HCR3rOhN9P1snG9OSwma0zEDw4Du0IqcLXLfAb/zc2E5S8yhyxnGKAD7QeLB/NJCLhCTT9giZ3/O+yaJuXwIiINqJl8Pm+3GfPBUzzHhr5xq+hD+R9QlXK4C+a7reqvCJcDF79jmLQwHaP0X3QWyZhCJOnNbesXQ4LtaZ05l/rG+77MLJOuxSkw/NucVjYaIsSFDadBXZNbd0zpvMTaIXtQfWgpJuBlkl8z82ay5HVOqLwrDxyt2cMbO5uxRW7efsjOoQS4tRLhW+OxeZA==
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(38070700021)(8096899003)(4053099003);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: URVD//P62JGB46MvIZEkUr2sq88Bqv7CZAo9gfjiZHPJU7MKqWYCGaS4lKL/3LSIBcJ8LAW6Y76ur98q2YQAdx3GZ21xGsxtttiSeKIQhmL+5FaPSRj6zwHg0UYilzdbcIbArDeKMQUAM8vtcSpJQwBB8Qtrhi2Dv0jFvyUlj6eie+wZqGx0zNkgDijTFxwS29xo3N1z7fdr1MkVOt/x+mMh2aQ211grZmumIxb2yMTrLyzE09ueSgEbmFopPy8C0n46Wn05rEyDWDsmr2OOOsV31juJhdK6FfF81ZA4BOzWhaWaqTq8CPVQMhKeDgvIU8mKb9dGef65JtZHJjnn2q/tEyrvVlyAspcgo7GLL8T6zUKve2CW2lXb2se9HJ2NUoPDHZi1sa7ZB4FSD8TBoLrDPLpnrEa1AQqu0x4cgt9dwfDW/E1P2mnr8BwzFQY58lJuSf3wEsU/5Aldd3zVeAnqI/c2zKbS6PTxusnkBQkJ33oc2Zg2tqIwEN3W4GsvTUGA/3H/CK3R344C26K8y67oLV2LpC2Wci3d1nY1CUbd3UhGCv/uQ8jrkxpZ/UocFiFLx3GGMMnBnI8CTaechO1fCpN18AdhOpSaj/M4/cHLRbbdO/rl91Ml8Fxj6rg1c1QS+h8XRBStLWDymwOrLWcGPv9G7aI3Vtbyfyz88XHJrrlPM3xFdP0/cUozFVaYBvJxHqky5abeQRRg/QZ0CREAhX+kbgeLXRSfsRAouiwHbR97/3Bfj2QIMoirluEyPIFiTELfDWVhKHFo76QrY2CjXKAQB/inFgtAYAV63fgXHD+KmJenLo204cZsVi6YOdf6jo+iYnXPLBvkvPjZylJ9y694VPp4H166A634P+RrqToTFuNy9FbsYo/MoxUDzGcpv3TWdP+aPZASZHQ/xgOSEZuJ3qVVExpFT8kUSxwO3q9sUyLrLsjHLSIJ6++1GEVWxXq0+0/XbsDBpJrH1+C5CqlVrqW8YDnDv6ET+MtT2DA8R74MVf4Rb2cke7+mUAtz/J5HdoZuVYpgcqjN1c9fVuXw6qiMnNkvBkhiHtXBHVDOV31YEOUKiYmKl5Y01qTrVjSZ0uE3B9ro9OJrHeiJiMBY9LTBo9avlpgPVletp6QQVmiLlXRr9Y7cQL9FcdjuK7pbftK5lTjyGwrXDbV4nvnqCYdyWPBr6I1izYNlEmNgnLlFZZXOWBS5ZxKv91Aql7gwmnNFQvOJvKC4Mb1tZoR5qnxCGqhTXz6/hOVZfcQg4yTPyj+KWsPf0aMuLTjQS+omuOTycP/cPMowea9vBYvACVCkxNdRqssBzYQSUdv6dJIPf4HlXlzQd4jOhHgkglt8HawjjHHt0yMtsfSnHUeT32BBPBWtE+LPMutFgod8/ndsMKPfcA57NqkqsoXTMzxOqrYtg8/L4KnrMCxvOTyRpLp+qQ4Cg3ReUNs9Hl+tPyAsdT73Y7HuUOUpxpBJjtR2ABMfktNaRnBYkSpx7/ZO9sbo1TYMtPfA1hM=
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="sha256"; boundary="_6FE36C64-E4D9-0E4F-886D-BEC13A44FBD9_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BN0P110MB1419.NAMP110.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 5c3120d4-453b-4b9e-78df-08de0a72f928
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Oct 2025 16:10:05.5757 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 83d1efe3-698e-4819-911b-0a8fbe79d01c
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA1P110MB1535
X-Proofpoint-GUID: 0eWAOfxGEj-M3tuKErKdnweDE0pxxURt
X-Proofpoint-ORIG-GUID: 0eWAOfxGEj-M3tuKErKdnweDE0pxxURt
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjUxMDEzMDA3MyBTYWx0ZWRfX/6H5IgaY/4zK pvIvoSZ80eyYndDlTLDXjdp2zHV8h60nsJBKHoUfozjOGAjrEc6Innl5Wgj1Vn724GCfmH8Bynq E0TG6/SoV8JzJXrVKNIvxvETD31bmMZP+FP9Z3nWU4Zbgaysq1FRwsrGAnh35jxtsNhw+sznHpR HI7z2iG2NN1UieTMNrso1KHoYP6/fDHyEsGqNFZ+8Mj4Yf1cJMByDlFY/utsvu0HkruT5j4q650 I5k7WQ3jM8IrOCXzwh0zZ2kt+dUQ8B9TTNtxMGn83U5mhmiADCCQ==
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1117,Hydra:6.1.9,FMLib:17.12.80.40 definitions=2025-10-13_06,2025-10-06_01,2025-03-28_01
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 adultscore=0 bulkscore=0 mlxlogscore=999 malwarescore=0 phishscore=0 suspectscore=0 mlxscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2510020000 definitions=main-2510130073
Message-ID-Hash: 52SH4XRRKFVHRGKWK3GO5PCITYJONACZ
X-Message-ID-Hash: 52SH4XRRKFVHRGKWK3GO5PCITYJONACZ
X-MailFrom: prvs=4381760925=uri@ll.mit.edu
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "tls@ietf.org" <tls@ietf.org>, "Andrei.Popov=40microsoft.com@dmarc.ietf.org" <Andrei.Popov=40microsoft.com@dmarc.ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group Last Call for Post-quantum Hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/OeElEpCYb1hwUTRJmJrj_BgxiBE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
> Yes , Hybrid is weaker because it contributes little/nothing[1] to cryptographic security and increases attack surface by adding another code base. Not quite. Certainly, the probability of a memory corruption bug increases, and this would be an actual threat. However, we are increasingly deploying memory safe languages. And if not, I seldomly see apps where the crypto is the one and only memory bug, or even a significant part of the attack surface. Crypto is not the “one and only memory bug” – true. But we do not hold off from removing bugs on the grounds that there likely remain other bugs still un-remedied. When it comes to other kinds of attacks, a properly designed hybrid can actually be *safer* because instead of doubling the amount of wall you have to guard for your castle, you are building a second wall *behind* an existing one. You need to maintain not one but two “walls” and worry about “interlacing/interfacing” between them. When you know that one of those walls is dead (well, not quite yet – but “terminally ill with no hope for recovery”), and all your future safety depends on the other wall. On a more technical level, the primary use of a KEM in TLS is to derive a secret key, and as long as the PQ-KEM spits out anything at all during normal program flow, whatever output this is could be treated as part of the nonce, as far as security goes. So the additional attack surface is basically nonexistent. Additional attack surface is not in the crypto theory, but in the implementation, particularly in the integrating the two “walls”. > [1] The only case when Hybrid helps is when both > CRQC is not a threat This is now for any use case not requiring confidentiality for more than a few years. Why would the users of that use case even bother with paying the cost of exchanged messages size increasing the by the orders of magnitude? For apparently zero benefit (as we don’t expect CRQC within the next few years)? > **and** PQ algorithms falls to a classic attack (like SIKE). Google KyberSlash, which is a classic attack. That's how realistic this is. That’s not an algorithmic attack – it’s an attack against implementations that have not plugged their timing side-channel. Such attacks exist against many (all?) Classic and PQ algorithms, they can be realistic, depending on your use case, and there are known defenses against them. > Thus, deploying hybrid because you want to protect your date against “harvest now, decrypt later” Quantum attack is a non-starter. And that attack is the main reason people are hustling now, rather than wait for several more years. "Harvest now, decrypt later" plays no role in deciding between a hybrid and an all-in option. It does, because in the end, only the PQ part determines whether your harvested-now data will remain safe or not. It plays a role in whether to deploy a PQ-resistant wall. The above attacks play a role in whether or not to deploy a tried-and-tested wall which we assume may fall one day. Hence, we erect both. It’s much more than “may fall one day” – any algorithm “falls” into this category. It’s a practical certainty that this (Classic) wall will fall, and probably sooner rather than later.
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Paul Wouters
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Working Group Last Call for Post-quantum Hy… Joseph Salowey
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… David Adrian
- [TLS] Re: Working Group Last Call for Post-quantu… Loganaden Velvindron
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Deirdre Connolly
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Bas Westerbaan
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Loganaden Velvindron
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… tirumal reddy
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Andrei Popov
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Thom Wiggers
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… David Benjamin
- [TLS] Re: [External⚠️] Re: Working Group Last Cal… Yaroslav Rosomakho
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Eric Rescorla
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: Working Group Last Call for Post-quantu… Martin Thomson
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Andrei Popov
- [TLS] Re: [External] Re: Working Group Last Call … D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Filippo Valsorda
- [TLS] Re: [External] Re: Working Group Last Call … Muhammad Usama Sardar
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: [External] Re: Working Group Last Call … John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Watson Ladd
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Yaroslav Rosomakho
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Dennis Jackson
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Stephen Farrell
- [TLS] Re: Working Group Last Call for Post-quantu… Joseph Birr-Pixton
- [TLS] Re: Working Group Last Call for Post-quantu… Robert Relyea
- [TLS] Re: [EXT] Re: [EXTERNAL] Re: Working Group … Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Sophie Schmieg
- [TLS] Re: Working Group Last Call for Post-quantu… Christopher Patton
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Muhammad Usama Sardar
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Viktor Dukhovni
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Deirdre Connolly
- [TLS] Re: [EXTERNAL] Re: Working Group Last Call … Rob Sayre
- [TLS] Appeal Response to Rob Sayre - was Re: Re: … Paul Wouters
- [TLS] Re: Appeal Response to Rob Sayre - was Re: … Rob Sayre
- [TLS] Re: Working Group Last Call for Post-quantu… Salz, Rich
- [TLS] Re: Working Group Last Call for Post-quantu… Blumenthal, Uri - 0553 - MITLL
- [TLS] Re: Working Group Last Call for Post-quantu… D. J. Bernstein
- [TLS] Re: Working Group Last Call for Post-quantu… Jan Schaumann
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… John Mattsson
- [TLS] Re: Working Group Last Call for Post-quantu… Peter Gutmann
- [TLS] Re: Working Group Last Call for Post-quantu… Yaakov Stein
- [TLS] Re: Working Group Last Call for Post-quantu… Kampanakis, Panos
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Bellebaum, Thomas
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Robert Relyea
- [TLS] Re: Working Group Last Call for Post-quantu… Kris Kwiatkowski
- [TLS] Re: Working Group Last Call for Post-quantu… Eric Rescorla
- [TLS] Re: Working Group Last Call for Post-quantu… Simon Josefsson
- [TLS] Re: Working Group Last Call for Post-quantu… Sophie Schmieg
- [TLS] Re: Working Group Last Call for Post-quantu… Alicja Kario
- [TLS] Re: Working Group Last Call for Post-quantu… Joseph Salowey