[TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa
Simon Josefsson <simon@josefsson.org> Thu, 28 May 2026 07:43 UTC
Return-Path: <simon@josefsson.org>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 9BA31F67EFAB; Thu, 28 May 2026 00:43:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779954215; bh=yzShqMbPD5ZBCmrdpKQ2wtQxshWbO1by1jdfuQYFnIc=; h=From:To:Cc:Subject:In-Reply-To:References:Date; b=b8bWfkFZN2B0ffbrcs9V81C4vsOczU9XtFva7n+vlHSTc6kAUMDybt2eLHyZwK7+B 4fA+wzJ3CADh7wDnlw4IFOjsTX9rSG0tvl3xqjrArB8bVbSpCsa8c45okHHVP9LZAT Q62kRR+tXX3aEW/mHb+vHqrCOZftJQ1ui8A5OeQo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.401
X-Spam-Level:
X-Spam-Status: No, score=-4.401 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=josefsson.org header.b="emI9G8fo"; dkim=pass (2736-bit key) header.d=josefsson.org header.b="l83o6egU"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id I4J6jvCMCnB5; Thu, 28 May 2026 00:43:34 -0700 (PDT)
Received: from uggla.sjd.se (uggla.sjd.se [IPv6:2001:9b1:8633::107]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 1B6DEF67EF97; Thu, 28 May 2026 00:43:34 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=ed2303; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=DS7LK13SoPncAy/bfokT0KtNRS7gIvY1qfRqSuc0IZ0=; t=1779954212; x=1781163812; b=emI9G8fobkDUugOKDTJvV4NKvGsVrtJ6Go22jursTae2OUm9C2NvEC32wrxUkChLveBVk5g8w17 6iUL/F64DAA==;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=rsa2303; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=DS7LK13SoPncAy/bfokT0KtNRS7gIvY1qfRqSuc0IZ0=; t=1779954212; x=1781163812; b=l83o6egUq7w6GZCpk70IpzJ8xU+FiUR5F45UVyCNOgfNuwWzU9/+m8t/oFiyHmZI2oI6Dpuz8// aKUctx5uKVj4iP8A9oE+qxdAaEtoEb1ulhC4Z0EQXInhw51M62VRWt+VYzF9F5bdiVjxJ8/Ux0KIn 80lnmzWsfWfvWdkMGDzjgA93IccYEkGnnAwhaVBqsduxjOPuiKBqNHy6XOH+7LgYN4HHl1XGDa5Eo I3nXtUte7TT2FjYPtNXuubaWmty/4zIRfEYP5OGK07I81n65c2c6O31VfFQmLCIjRJyao4Gakvjk4 vySFDBz8hLvRx4hit9Zm4zFqJyZFxDP956VUcJXEToW7eQLqd31PO9jjkjvasiMDuxgodqkxN3L2z khSURZuB0kJHJ4Ra8nJ3y9CghrBaI+a60+QH07zwhN5yKYjUBbRq6hUADkvXc8rPSA/tdAG4G;
Received: from h-178-174-130-130.a498.priv.bahnhof.se ([178.174.130.130]:42168 helo=frallan) by uggla.sjd.se with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from <simon@josefsson.org>) id 1wSVOq-006Rl5-Mj; Thu, 28 May 2026 07:43:28 +0000
From: Simon Josefsson <simon@josefsson.org>
To: Watson Ladd <watsonbladd@gmail.com>
In-Reply-To: <CACsn0cmaOdG4vCdeOVSxAPnJtPRH8rBJ3sfAY3o0f1fm-ouceg@mail.gmail.com> (Watson Ladd's message of "Wed, 27 May 2026 14:01:08 -0700")
References: <20260519112813.1254795.qmail@cr.yp.to> <CAGgd1Ocy8f4HeQy-qWauAJAxizznXdXA53kWVp_FV1QUVGuxWw@mail.gmail.com> <5DFBF81F-4A98-4C5E-A060-580DC6960021@symbolic.software> <87v7c8lgt8.fsf@josefsson.org> <CACsn0cmaOdG4vCdeOVSxAPnJtPRH8rBJ3sfAY3o0f1fm-ouceg@mail.gmail.com>
OpenPGP: id=B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE; url=https://josefsson.org/key-20190320.txt
X-Hashcash: 1:23:260528:iesg@ietf.org::Q6NOPlvGkwtcCZZ+:1k8B
X-Hashcash: 1:23:260528:stndrds-inacio@andrew.cmu.edu::KCQH/FLPKoZEP1Yz:0+KI
X-Hashcash: 1:23:260528:djb@cr.yp.to::tE12vUbDAGnHaKCO:4bD0
X-Hashcash: 1:23:260528:watsonbladd@gmail.com::g939h8uS9K/RxtaY:3uo6
X-Hashcash: 1:23:260528:simon=40josefsson.org@dmarc.ietf.org::DV0phgx3tWMx0Tq0:90GU
X-Hashcash: 1:23:260528:tls@ietf.org::WKHjA+91XjgkU6lh:9IGw
X-Hashcash: 1:23:260528:nadim@symbolic.software::k8XEFPvF4/nLYNxi:5LY6
Date: Thu, 28 May 2026 09:43:29 +0200
Message-ID: <871pewkmhq.fsf@josefsson.org>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Message-ID-Hash: NWDWOPFBCE2OLE6ZORAHUWFWRUSHXCLE
X-Message-ID-Hash: NWDWOPFBCE2OLE6ZORAHUWFWRUSHXCLE
X-MailFrom: simon@josefsson.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Nadim Kobeissi <nadim@symbolic.software>, TLS List <tls@ietf.org>, "D. J. Bernstein" <djb@cr.yp.to>, stndrds-inacio@andrew.cmu.edu, "<iesg@ietf.org>" <iesg@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Complaint to ADs and IESG regarding TLS WG chairs falsely claiming WG consensus to issue an RFC for draft-ietf-tls-mldsa
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/nr4p0LTMe5HjB50Ezh6NMYJBNU0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>
Watson Ladd <watsonbladd@gmail.com> writes: >> Repeating that statement doesn't make it true. The analog motivation >> for doing PQ hybrids is Man-In-The-Middle attacks. If your non-hybrid >> PQ signature has a weakness (e.g., implementation bug), it facilitate >> man-in-the-middle's. >> > > The only way to achieve that is to have a quantum computer at the time of > attack No that's totally wrong, and appears to be a common fallacy. One likely scenario is to use a traditional computer to break the PQ part and establish a MITM. Reaching confidence in crypto takes time. We need confidence in: - Underlying math problem (factoring, disclog, lattices) - Algorithm (RSA-PKCSv1.5, RSA-PSS, ECDSA, EdDSA, etc) - Parameter selection (512-bit RSA, 1024-bit RSA, secp128, etc) - Implementation (side channels, correctness, corner cases, parametrization bugs, API issues prehash vs non-prehash etc) It took perhaps ~30 years to arrive at RSA-PSS-4096. Common choices ~20 years (RSA PKCSv1.5 1024-bit) ago is considered insecure today, and allows a MITM. Did it take ~25 years to reach the same for ECDSA? secp256. Common choces ~13 years ago (secp192/secp224) is considered insecure today, and allows a MITM. For Ed25519 the design has been stable since the initial publication 2011 (a remarkable achievement), but I'd say it took ~10 years to reach maturity. Fortunately Ed448 did not introduce parametrization bugs in implementations. The HashEdDSA mode of RFC8032 introduced an API weakness. Non-deterministic "hedged" use introduce another weakness. For ML-DSA the spec was published in August 2024 and the final stable test vectors not available significantly earlier. Even if we collectively entertain our hybris and believe that FIPS204 will stand the test of time as well as Ed25519 have, we are looking at least at a 5-10 year window where history tells us to be careful. This window of opportunity is known to HNDL attackers today. Using ML-DSA in non-hybrid mode gives them same windows of opportunity to mount MITM during the next 5-15 years. I believe granting that attack vector is entirely irresponsible. Several organizations has funding, purchasing power and demonstrated historical track record to influence the IETF to make weak choices. /Simon
- [TLS] Complaint to ADs and IESG regarding TLS WG … D. J. Bernstein
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Soatok Dreamseeker
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Muhammad Usama Sardar
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nadim Kobeissi
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nadim Kobeissi
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Deb Cooley
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nadim Kobeissi
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Simon Josefsson
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Watson Ladd
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nico Williams
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Watson Ladd
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nico Williams
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Watson Ladd
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Eric Rescorla
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Eric Rescorla
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nico Williams
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Martin Thomson
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Simon Josefsson
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Ilari Liusvaara
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Joseph Birr-Pixton
- [TLS] Re: Complaint to ADs and IESG regarding TLS… John Mattsson
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Tibor Jager
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Bas Westerbaan
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Daniel Apon
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Daniel Apon
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Tibor Jager
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Daniel Apon
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Simon Josefsson
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Salz, Rich
- [TLS] Re: Complaint to ADs and IESG regarding TLS… Nico Williams
- [TLS] Re: Complaint to ADs and IESG regarding TLS… IETF Chair
- [TLS] Re: Complaint to ADs and IESG regarding TLS… IETF Chair