[TLS] Re: [EXT] Re: [Last-Call] <draft-ietf-tls-mldsa-03.txt> (Use of ML-DSA in TLS 1.3) to Informational RFC

Brian E Carpenter <brian.e.carpenter@gmail.com> Wed, 27 May 2026 07:24 UTC

Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C99E5F5C32B0 for <tls@mail2.ietf.org>; Wed, 27 May 2026 00:24:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779866666; bh=rOyVvHwY0L5ujj91l8IQlAGSVkF9sImEsrmCduZGwF0=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=zW3lrmS7jquaGVu4zN6VHmLWheiM5Px9tN3Rw+IQFiNF4oL/1sOdkpy1h4HcKXqjM Cc5qhIUeXGsEeX9ouDnaT9IjtMhYMf6L7kYenxkJErOxbh0X2fusx16nmtShrBcVwl fAMWKYIRhcehRns86Z/h1jl6eDfcB4tuvR7J18kw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UweHmJTb03af for <tls@mail2.ietf.org>; Wed, 27 May 2026 00:24:26 -0700 (PDT)
Received: from mail-pf1-x429.google.com (mail-pf1-x429.google.com [IPv6:2607:f8b0:4864:20::429]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 6A02BF5C32A8 for <tls@ietf.org>; Wed, 27 May 2026 00:24:26 -0700 (PDT)
Received: by mail-pf1-x429.google.com with SMTP id d2e1a72fcca58-8353c9f24d2so5747906b3a.3 for <tls@ietf.org>; Wed, 27 May 2026 00:24:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779866665; x=1780471465; darn=ietf.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=rOyVvHwY0L5ujj91l8IQlAGSVkF9sImEsrmCduZGwF0=; b=Y0wJ7Y9z0rr8W7OOG+AfQm41jooYejq2c8+c5xBt+St2UPj/xgJc0wFkITO5cVcTDb ftDrvALBszLCIYKmE6V/9bWpThurn6eEuXY9H6zPtOlKyY4VodEb5/FDiAct08GueMGj mhKjfq5HcFI8y21mU3ruPjecJgds3D+l9oPCcoXUuSSOatd62V3k96xJ/dCh9weM72Jl O7qYIDo8rvYhwW/UjZOCz8nYa+a64p+XiymOAIsW3RiT/z1KtrRg1n6FcTEZ4px62Lww 3XlYTfLaFBVzQgMtayiYfYHWHh7eDwp6VpTt1tp3+KzxK3wDqc6WRQFyrPFGsFgVwINK vWPA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779866665; x=1780471465; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=rOyVvHwY0L5ujj91l8IQlAGSVkF9sImEsrmCduZGwF0=; b=HjPZzaJQjuc3ZWH8YwPjTzvas7TPEea6m5dtcexQrXpbTj/FCEvNRFLGnriFfQa0RO UrCOUZ4n6KLK2tCKLlkbz60eBNU9CgjLjNN87HJfAX8CShipE5Mic4DEnQNyoA1CDbAQ /gHuH6IVb3bIsC8UYAd16zay/w2qqK5/nqNkNDNM0GMmE4f0ojGPaEAvnXbI7axbSBo0 eW8Lr8RBwq5S73CR+17h63A6uw23Q48FgbFzlJtKQ5Xj12L4VwtiiECaSpxfG2f4XBo1 J3i7tVhk/YG/g17gMq8N+vCqoBrD+HWSqNfNDq2CoQzBQJ4AYV9AIBRZjI+HfAqLWl/b pybQ==
X-Gm-Message-State: AOJu0YwU7/W7iluDt9uuDMVXiHVnwPRzcmMXUHz6iCL6KZwuol5FIK7o rTIjBSca/lMduTHlvMhzc84f4y9nnL2NmqIyepKXFDJ16WtxHwXN9c+z
X-Gm-Gg: Acq92OETHgO6DI1ppNa/GybyFowM93EA5dSn+d5ZQaz5hbykuWiWziLO4d76a5VYqdS B5+wNSUAJ4OH/cJ5CViA/Iw9cTdB3KgyL0u5us2brDsgiMmphTXVbSbzFkXUXudODiYtVJTsrcg lqHHj9SLrvzuG+llIBd2X4lqT9Er0Bmc11V69MGAR01fXjOiYxRH4vmFeFjOsu9nA9O5GWLL3pG IQJD6WXVyfRaCIG+DwYY90jhHIRgY9VSZpWNOgcHRgK85lkUeTc3+58w5hzvyCw/i+bfowvCWzZ ryNTwnutLV8pfF3x/QlNGDazf7pvFBUfTiOtSeRugRgNZ338vLhRJy+m4Y924h0WpYsUMLtkNdi u5iZc23x6eLRkBUYNzgRIDDj0E1QNZX40+4Js/hTQns03ZKcQrpqEQ/1og783HbgHT6lHBKyAdn pluVxneL9R25NV/dIaPF/PokzmZlOs3dU5su7d3v5li0AmHv+fe8TWNoO7+e4q/7oU7EGn8ETYm 21Ekje8T7LWg6xPMbskDL4P/JOz
X-Received: by 2002:a05:6a00:189e:b0:82f:316:3206 with SMTP id d2e1a72fcca58-8415f54464cmr20943045b3a.34.1779866665319; Wed, 27 May 2026 00:24:25 -0700 (PDT)
Received: from ?IPV6:2404:4400:a100:1829:5956:ca53:df83:6568? ([2404:4400:a100:1829:5956:ca53:df83:6568]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-841d6e82323sm1432971b3a.2.2026.05.27.00.24.22 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 27 May 2026 00:24:24 -0700 (PDT)
Message-ID: <12a33cf8-6ace-4853-a8f7-098302b6746d@gmail.com>
Date: Wed, 27 May 2026 19:24:20 +1200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: John Mattsson <john.mattsson@ericsson.com>, Deirdre Connolly <durumcrustulum@gmail.com>, Rob Sayre <sayrer@gmail.com>
References: <AS4PR07MB8825195C332703D5768B076489082@AS4PR07MB8825.eurprd07.prod.outlook.com>
Content-Language: en-US
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
In-Reply-To: <AS4PR07MB8825195C332703D5768B076489082@AS4PR07MB8825.eurprd07.prod.outlook.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: base64
Message-ID-Hash: PZ4DLN27X5KS32N2IWFTRCIKY55QQIDX
X-Message-ID-Hash: PZ4DLN27X5KS32N2IWFTRCIKY55QQIDX
X-MailFrom: brian.e.carpenter@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "TLS@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: [EXT] Re: [Last-Call] <draft-ietf-tls-mldsa-03.txt> (Use of ML-DSA in TLS 1.3) to Informational RFC
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/b2DhuOaIYOSLkVxL4VU7F2qaYYU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

John, I appreciate your clarifications, I really do. It all serves to show why we need an accessible exposition of these issues for the non-expert readers of the relevant RFCs.

Regards/Ngā mihi
    Brian Carpenter

On 27-May-26 18:47, John Mattsson wrote:
> Brian E Carpenter wrote:
>  >The 'significantly harder' argument, which requires that independence, is that if the probablity of one being broken over the next n years is p, and the probability of the other being broken over the next n years is q, then the probability of both being broken is pq.
> 
> Why do you insist on making comparisons to basic mathematical operations that do not apply to cryptographic compositions?
> 
> - If the probability of finding a distinguishing attack on encryption algorithm A is p, and the probability of finding a distinguishing attack on an independent encryption algorithm B is q, then the probability of finding a distinguishing attack on the composition B(A(P)) is not pq. Depending on the algorithms and the composition method, the probability can clearly be q, or smaller than pq.
> 
> - Similarly, if the probability of finding a malleability attack on EdDSA is p, and the probability of finding a malleability attack on ML-DSA is q, then the probability of finding a malleability attack on draft-ietf-lamps-pq-composite-sigs is not pq, it is 1.
> 
> Cryptographic composition is fundamentally different from ordinary arithmetic. Security properties do not combine linearly, multiplicatively, or even monotonically. Composing two schemes can preserve security, weaken security, destroy specific security properties entirely, or introduce completely new attack surfaces. That is precisely why simplistic analogies to addition or multiplication are misleading in this context.
> 
> Cheers,
> John Preuß Mattsson
> 
>