[TLS] Re: WG Adoption Call for ML-KEM Post-Quantum Key Agreement for TLS 1.3

Loganaden Velvindron <loganaden@gmail.com> Thu, 17 April 2025 15:43 UTC

Return-Path: <loganaden@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 15FC31DB01AC for <tls@mail2.ietf.org>; Thu, 17 Apr 2025 08:43:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2qLj3IHyRybW for <tls@mail2.ietf.org>; Thu, 17 Apr 2025 08:43:38 -0700 (PDT)
Received: from mail-pf1-x42b.google.com (mail-pf1-x42b.google.com [IPv6:2607:f8b0:4864:20::42b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BEE4E1DB01A0 for <tls@ietf.org>; Thu, 17 Apr 2025 08:43:38 -0700 (PDT)
Received: by mail-pf1-x42b.google.com with SMTP id d2e1a72fcca58-736c1138ae5so859311b3a.3 for <tls@ietf.org>; Thu, 17 Apr 2025 08:43:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1744904618; x=1745509418; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=03Aa6jJ9mw4Bh2kBfGEv1HCaWlRbWPYwAcBSwMmt7N8=; b=RXhyCBxLvL+XcTJYq/ePvW0NflncHQPlC/2LEF2UqExcwKNDvwsTBIQAEZfxAbDNdm boWrGowvhnSyPwc/fUZ6bIh0eD5PMpBrc4u/BeUM9m4BMsRVifAjlw5X+E7SwfiIE+gS PWoSlCXLajU/3dpLOZiK4FgFI5sgHJ4b1TZkLtphJYotzu7k3yW7+lp6GnsPckrTgcj0 V6IIzZjVKm0C2bfXk4tKWv3QH5kK7X8db/Tq2YaBnCEcHikg0BGdeMW1DxkVt4HxYExV Fvx7ufBBpppIz9N+/30wPFMdMHqLvPRG7wnw7l4ACLlkQwxSfVD3NbqzLIUFNDa5SQK9 Rfiw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1744904618; x=1745509418; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=03Aa6jJ9mw4Bh2kBfGEv1HCaWlRbWPYwAcBSwMmt7N8=; b=VLOvLryeN5KquYuVQuz9H6WCyt4Frx+X6MUkAmt7fGOybIYnmMz/+kq67zkLNojqbP BZsUNdde/Y5AcMx4lGnu3JNjk1i4qVwRdyNvMyW3c4yFFXWgbVKIGrADFKMViVmkqSK+ UUthsxAX0VoQSOUxK0SYaTEAfLK0Bg/kxRZuPnBbtoFqaOer20ndaZtiEG8HeUMXoP7R GTODaPeGyktp0DPyKSWwkOiiQxBMAU2JBFeF/IMw0odOpHuYsQDVvwDT7iCFRnlh+YLd a+BkGn60UuXibZQsTzCcHMrPTApCZWXqh9d/88p9xENGeoSG+rGSyhI+PksmDlSQMBso cUqw==
X-Forwarded-Encrypted: i=1; AJvYcCXOwqQ5+cpx0MbZKjGJZwRjjdvxYo0UUmpFKs6s74eLzEoQ6M1yNeJnnXfVdeR2VuO/bzA=@ietf.org
X-Gm-Message-State: AOJu0YwF9M0PMGbmFQ/4KqpVfgTRo2l7ABtft37P8kyiN+3mkDe0cB2w M3gbGX6zKS0W5gqFe2ad8lz/0/+YMffLmTX0WALZ2C+jfh40tGuUkmrOYED3l8GuWn3lqAWmuc+ aOVpP3+JOe0X4QYq4Jx6mu2myJLc=
X-Gm-Gg: ASbGnctO77s0yCDgD1J7S5iJzPGc8/1hwyQpgCSnoph1+pTSiBoar2e8s6YiYb+08Wg iC/DhLcoULttIbM5P/Al/KbJHF/0UEH6t6jpKaFYWuaZbnC+vB/f6S2qNi01uOnDPkkWTkMvl9e Khfnn0IfvbgO7ePG9og1FosyGvVLgrCeN1dufC/yH7t9UyOItNZ2yf44O+lD8=
X-Google-Smtp-Source: AGHT+IF1sICzswkacZ6n+ADLwPQcc0hK++DTRho2zc8ygu8TRWll2qCsWesDCCOe6lsUYJGUQmxuII6k3M2kun4JZWQ=
X-Received: by 2002:a05:6a00:aa8d:b0:736:a973:748 with SMTP id d2e1a72fcca58-73c267f8ba4mr9154753b3a.22.1744904617740; Thu, 17 Apr 2025 08:43:37 -0700 (PDT)
MIME-Version: 1.0
References: <5dd1e81a-c37a-ceff-b89e-b4335fca07b6@nohats.ca> <56e646395f67e27ff11a092d5989c1c85eba2563.camel@aisec.fraunhofer.de>
In-Reply-To: <56e646395f67e27ff11a092d5989c1c85eba2563.camel@aisec.fraunhofer.de>
From: Loganaden Velvindron <loganaden@gmail.com>
Date: Thu, 17 Apr 2025 19:43:25 +0400
X-Gm-Features: ATxdqUEvp7cNbb_4NpLSGj6KRfGxldbTXeSM3-0tDNUC-xywLMDa4rxhte8G6yI
Message-ID: <CAOp4FwSJpvn6f=3utd4yBE=ftkXQ4h38FT3VQ1XOhrubqgu0ng@mail.gmail.com>
To: "Bellebaum, Thomas" <thomas.bellebaum@aisec.fraunhofer.de>
Content-Type: text/plain; charset="UTF-8"
Message-ID-Hash: HAC6TCRRZ4CNW3LOV6VHMI5MNNFCYTCT
X-Message-ID-Hash: HAC6TCRRZ4CNW3LOV6VHMI5MNNFCYTCT
X-MailFrom: loganaden@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "paul.wouters@aiven.io" <paul.wouters@aiven.io>, "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Adoption Call for ML-KEM Post-Quantum Key Agreement for TLS 1.3
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/QDt7s48VIHgqgdgh3V5yjej2jbQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

On Thu, 17 Apr 2025 at 14:02, Bellebaum, Thomas
<thomas.bellebaum@aisec.fraunhofer.de> wrote:
>
> I am sorry for interrupting your argument, but as you are discussing this on-list:
>
> > My previous email explained the obvious way the consensus was validly called. This
> > can be independently verified by anyone reading the email thread. The
> > fact that you are the only one questioning the consensus should be an
> > indication that your reasoning to doubt the consensus call might in fact
> > be erroneous.
>
> He is not the only one. Using the independently verifiable mail thread, I actually did count by a rough look over the messages (sorry if I missed/misinterpreted someone):
>
> Pro Adoption:
> - Alicja Kario
> - Andrei Popov
> - David Adrian
> - Filippo Valsorda
> - Flo D
> - Jan Schaumann
> - John Mattson
> - Joseph Birr-Pixton
> - Kris Kwiatkowski
> - Loganaden Velvindron
I don't see it as a Pro/Against Adoption issue. It's more subtle than
this. I'm definitely
a Pro Hybrid but I understand that  vendors need pure PQ  to sell to a
very large government.


However, the approach of pure PQ carries risks. The risks are
amplified if this is deployed
into consumer products where billions of users are not aware of the
current issues discussed in this thread.

The whole debate has put me in a somewhat difficult position. There is
a lot of context that needs to be taken into
consideration.