[TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa

Simon Josefsson <simon@josefsson.org> Thu, 28 May 2026 07:43 UTC

Return-Path: <simon@josefsson.org>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 9BA31F67EFAB; Thu, 28 May 2026 00:43:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779954215; bh=yzShqMbPD5ZBCmrdpKQ2wtQxshWbO1by1jdfuQYFnIc=; h=From:To:Cc:Subject:In-Reply-To:References:Date; b=b8bWfkFZN2B0ffbrcs9V81C4vsOczU9XtFva7n+vlHSTc6kAUMDybt2eLHyZwK7+B 4fA+wzJ3CADh7wDnlw4IFOjsTX9rSG0tvl3xqjrArB8bVbSpCsa8c45okHHVP9LZAT Q62kRR+tXX3aEW/mHb+vHqrCOZftJQ1ui8A5OeQo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.401
X-Spam-Level:
X-Spam-Status: No, score=-4.401 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=josefsson.org header.b="emI9G8fo"; dkim=pass (2736-bit key) header.d=josefsson.org header.b="l83o6egU"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id I4J6jvCMCnB5; Thu, 28 May 2026 00:43:34 -0700 (PDT)
Received: from uggla.sjd.se (uggla.sjd.se [IPv6:2001:9b1:8633::107]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 1B6DEF67EF97; Thu, 28 May 2026 00:43:34 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=ed2303; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=DS7LK13SoPncAy/bfokT0KtNRS7gIvY1qfRqSuc0IZ0=; t=1779954212; x=1781163812; b=emI9G8fobkDUugOKDTJvV4NKvGsVrtJ6Go22jursTae2OUm9C2NvEC32wrxUkChLveBVk5g8w17 6iUL/F64DAA==;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=rsa2303; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=DS7LK13SoPncAy/bfokT0KtNRS7gIvY1qfRqSuc0IZ0=; t=1779954212; x=1781163812; b=l83o6egUq7w6GZCpk70IpzJ8xU+FiUR5F45UVyCNOgfNuwWzU9/+m8t/oFiyHmZI2oI6Dpuz8// aKUctx5uKVj4iP8A9oE+qxdAaEtoEb1ulhC4Z0EQXInhw51M62VRWt+VYzF9F5bdiVjxJ8/Ux0KIn 80lnmzWsfWfvWdkMGDzjgA93IccYEkGnnAwhaVBqsduxjOPuiKBqNHy6XOH+7LgYN4HHl1XGDa5Eo I3nXtUte7TT2FjYPtNXuubaWmty/4zIRfEYP5OGK07I81n65c2c6O31VfFQmLCIjRJyao4Gakvjk4 vySFDBz8hLvRx4hit9Zm4zFqJyZFxDP956VUcJXEToW7eQLqd31PO9jjkjvasiMDuxgodqkxN3L2z khSURZuB0kJHJ4Ra8nJ3y9CghrBaI+a60+QH07zwhN5yKYjUBbRq6hUADkvXc8rPSA/tdAG4G;
Received: from h-178-174-130-130.a498.priv.bahnhof.se ([178.174.130.130]:42168 helo=frallan) by uggla.sjd.se with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from <simon@josefsson.org>) id 1wSVOq-006Rl5-Mj; Thu, 28 May 2026 07:43:28 +0000
From: Simon Josefsson <simon@josefsson.org>
To: Watson Ladd <watsonbladd@gmail.com>
In-Reply-To: <CACsn0cmaOdG4vCdeOVSxAPnJtPRH8rBJ3sfAY3o0f1fm-ouceg@mail.gmail.com> (Watson Ladd's message of "Wed, 27 May 2026 14:01:08 -0700")
References: <20260519112813.1254795.qmail@cr.yp.to> <CAGgd1Ocy8f4HeQy-qWauAJAxizznXdXA53kWVp_FV1QUVGuxWw@mail.gmail.com> <5DFBF81F-4A98-4C5E-A060-580DC6960021@symbolic.software> <87v7c8lgt8.fsf@josefsson.org> <CACsn0cmaOdG4vCdeOVSxAPnJtPRH8rBJ3sfAY3o0f1fm-ouceg@mail.gmail.com>
OpenPGP: id=B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE; url=https://josefsson.org/key-20190320.txt
X-Hashcash: 1:23:260528:iesg@ietf.org::Q6NOPlvGkwtcCZZ+:1k8B
X-Hashcash: 1:23:260528:stndrds-inacio@andrew.cmu.edu::KCQH/FLPKoZEP1Yz:0+KI
X-Hashcash: 1:23:260528:djb@cr.yp.to::tE12vUbDAGnHaKCO:4bD0
X-Hashcash: 1:23:260528:watsonbladd@gmail.com::g939h8uS9K/RxtaY:3uo6
X-Hashcash: 1:23:260528:simon=40josefsson.org@dmarc.ietf.org::DV0phgx3tWMx0Tq0:90GU
X-Hashcash: 1:23:260528:tls@ietf.org::WKHjA+91XjgkU6lh:9IGw
X-Hashcash: 1:23:260528:nadim@symbolic.software::k8XEFPvF4/nLYNxi:5LY6
Date: Thu, 28 May 2026 09:43:29 +0200
Message-ID: <871pewkmhq.fsf@josefsson.org>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Message-ID-Hash: NWDWOPFBCE2OLE6ZORAHUWFWRUSHXCLE
X-Message-ID-Hash: NWDWOPFBCE2OLE6ZORAHUWFWRUSHXCLE
X-MailFrom: simon@josefsson.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Nadim Kobeissi <nadim@symbolic.software>, TLS List <tls@ietf.org>, "D. J. Bernstein" <djb@cr.yp.to>, stndrds-inacio@andrew.cmu.edu, "<iesg@ietf.org>" <iesg@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/nr4p0LTMe5HjB50Ezh6NMYJBNU0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Watson Ladd <watsonbladd@gmail.com> writes:

>> Repeating that statement doesn't make it true.  The analog motivation
>> for doing PQ hybrids is Man-In-The-Middle attacks.  If your non-hybrid
>> PQ signature has a weakness (e.g., implementation bug), it facilitate
>> man-in-the-middle's.
>>
>
> The only way to achieve that is to have a quantum computer at the time of
> attack

No that's totally wrong, and appears to be a common fallacy.

One likely scenario is to use a traditional computer to break the PQ
part and establish a MITM.

Reaching confidence in crypto takes time.  We need confidence in:

- Underlying math problem (factoring, disclog, lattices)
- Algorithm (RSA-PKCSv1.5, RSA-PSS, ECDSA, EdDSA, etc)
- Parameter selection (512-bit RSA, 1024-bit RSA, secp128, etc)
- Implementation (side channels, correctness, corner cases,
  parametrization bugs, API issues prehash vs non-prehash etc)

It took perhaps ~30 years to arrive at RSA-PSS-4096.  Common choices ~20
years (RSA PKCSv1.5 1024-bit) ago is considered insecure today, and
allows a MITM.

Did it take ~25 years to reach the same for ECDSA?  secp256.  Common
choces ~13 years ago (secp192/secp224) is considered insecure today, and
allows a MITM.

For Ed25519 the design has been stable since the initial publication
2011 (a remarkable achievement), but I'd say it took ~10 years to reach
maturity.  Fortunately Ed448 did not introduce parametrization bugs in
implementations.  The HashEdDSA mode of RFC8032 introduced an API
weakness.  Non-deterministic "hedged" use introduce another weakness.

For ML-DSA the spec was published in August 2024 and the final stable
test vectors not available significantly earlier.

Even if we collectively entertain our hybris and believe that FIPS204
will stand the test of time as well as Ed25519 have, we are looking at
least at a 5-10 year window where history tells us to be careful.

This window of opportunity is known to HNDL attackers today.

Using ML-DSA in non-hybrid mode gives them same windows of opportunity
to mount MITM during the next 5-15 years.

I believe granting that attack vector is entirely irresponsible.

Several organizations has funding, purchasing power and demonstrated
historical track record to influence the IETF to make weak choices.

/Simon