[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

Charles Cazabon <charlesc-ietf.org@pyropus.ca> Wed, 01 July 2026 20:10 UTC

Return-Path: <charlesc-ietf.org@pyropus.ca>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id BCFFC10BCCD39 for <tls@mail2.ietf.org>; Wed, 1 Jul 2026 13:10:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1782936648; bh=CKfJ5hh5pVzoRZ2IOfl287H//QjUb0C0vk1ODsOE4Nw=; h=Date:From:To:Subject; b=rB4EYo31PDQWBOz2nNg+JhS6SDxxQpwM5Em65MOTUmBK1ocH2jHWlw1UJz1+L5GgB 44yH24cZtdGM8gAcEnVUR8h76CuJahcmiO0Dkwgh+Z6Rm/VufUZMFSj0xweRZgS9L8 O+EGwVBzU7IKch5BKpbVEiF7PSYi2r4S101PMV8Y=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.398
X-Spam-Level:
X-Spam-Status: No, score=-4.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=pyropus.ca
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G15pmHGqjNBI for <tls@mail2.ietf.org>; Wed, 1 Jul 2026 13:10:48 -0700 (PDT)
Received: from detritus.pyropus.ca (detritus.pyropus.ca [96.126.125.117]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id EB2AF10BCCBE6 for <tls@ietf.org>; Wed, 1 Jul 2026 13:10:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=pyropus.ca; i=@pyropus.ca; q=dns/txt; s=v20220906; t=1782936642; h=from : to : cc : subject : date : message-id; bh=CKfJ5hh5pVzoRZ2IOfl287H//QjUb0C0vk1ODsOE4Nw=; b=LESdalz2Ry+umN8xz+GddCexpbhsnMgxrJxmuLr2nxw6Iizuuk8JCtTTGY/PbOuW7Khpe h0KCSOuDByAEF9wyMwWdTHe5PVmXa5oS7Y5M971rV4vF8T2PZ+J5EnJXvZxDRN3p5zOVmIi D8Jy4LWayjUDaDMY9z9m9xA4pDZ0YX1rJaYooRpxdc9KVQJ7amoHNjLQlnlINVknvqzgrZL 4zDV0H4kasKLoNC5nQtBw1ToNCdD8/V44dRTGvA/8Qmjy6+U8pMWcSd0EM4rOEL9LAvH//X /7IgqId6rcusKnJXcJf48+qZFtMOAdXUtA8R0JdpsfiDTWbanCUm0/+cqxMg==
Received: (qmail 2198244 invoked from network); 1 Jul 2026 17:24:01 -0000
Received: from 204-83-171-87.regn.static.sasknet.sk.ca (HELO lipwig.pyropus.ca) (204.83.171.87) by detritus.pyropus.ca with SMTP; 1 Jul 2026 17:24:01 -0000
Received: (qmail 1084123 invoked from network); 1 Jul 2026 17:24:01 -0000
Received: from internal (HELO vetinari.pyropus.ca) (10.0.0.2) by lipwig.pyropus.ca with SMTP; 1 Jul 2026 17:24:01 -0000
Date: Wed, 01 Jul 2026 11:24:00 -0600
From: Charles Cazabon <charlesc-ietf.org@pyropus.ca>
To: IETF TLS mailing list <tls@ietf.org>
Message-ID: <95118d2a-8663-4ab9-a778-b87c1c87ff06@pyropus.ca>
Mail-Followup-To: IETF TLS mailing list <tls@ietf.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
Message-ID-Hash: 3VSJLMAMDD6QSTROTHU26RTWZK66YSLM
X-Message-ID-Hash: 3VSJLMAMDD6QSTROTHU26RTWZK66YSLM
X-MailFrom: charlesc-ietf.org@pyropus.ca
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/VW_hwAYt_-XQ4G4yHnciJe_UF90>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

I do not support publishing this document.

The costs of using PQ+ECC are known and minimal, while providing significant
"belt and braces" backup security practices if the PQ primitive fails.  This
document advocates removing that backup for no clear benefit and significant
additional risk.  Given the chances that the PQ specification and
implementation are both not subject to future successful attacks are
approximately zero, I see no reason to recommend anyone implement PQ without
an ECC backup.

Charles
-- 
------------------------------------------------------------------
Charles Cazabon                     <charlesc-ietf.org@pyropus.ca>
Software, consulting, and services available at http://pyropus.ca/
------------------------------------------------------------------