[TLS] Re: Composite ML-DSA

Simon Josefsson <simon@josefsson.org> Wed, 15 April 2026 14:50 UTC

Return-Path: <simon@josefsson.org>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 3CBE3DCD2700; Wed, 15 Apr 2026 07:50:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1776264653; bh=urDh0fuTiZVxn5b2xG6ze3Hs7pwtLJmAdK7Ow5ZNMEU=; h=From:To:Cc:Subject:In-Reply-To:References:Date; b=eZbj5QRIR2T8CQm4s59XF/Ua0WTz1ysvCdV2BYFkENrGwV2qdAPi6PotEEEm076QQ CY/1rjL7RbFpmpH0QKwhfDmFkOd19OnSj508yWThqtKrWK+tSTIaeMozpJPuqJ+tx5 +mVcrkjVLkeJXNrvAY89SB9LvKHeukbPOjSPVxzs=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.401
X-Spam-Level:
X-Spam-Status: No, score=-4.401 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=josefsson.org header.b="ZgmqjAej"; dkim=pass (2736-bit key) header.d=josefsson.org header.b="wb9flmuH"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xffXTwNVLBoW; Wed, 15 Apr 2026 07:50:51 -0700 (PDT)
Received: from uggla.sjd.se (uggla.sjd.se [IPv6:2001:9b1:8633::107]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D315EDCD254F; Wed, 15 Apr 2026 07:49:40 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=ed2303; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=Hyiooufy7tdayM9jPF6f999Al1xJFfrCHe+BLlwi+b4=; t=1776264566; x=1777474166; b=ZgmqjAejNtdNz1YD6XT2pHZN9Q3/zFxU2ug5aAJP1Lxqq9dO7X/E2BuMKhf8yf5Y0tYyiWWHePg xklRqL2XsBw==;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=josefsson.org; s=rsa2303; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=Hyiooufy7tdayM9jPF6f999Al1xJFfrCHe+BLlwi+b4=; t=1776264566; x=1777474166; b=wb9flmuHtVImhdm5TcWK4vm43Sid7adGPzf9y86ijAkWBNpD3dk3fbPH2TyezZBxw+mQ4u+5Hbw Jyf37aEEuk+POS+QYd0kCf+O6dcVbQjUDnZtTReIZNov1ErdFxtwiXp5Dvs9ZoTZ9Q952JKAmuAqm hPAVAWDs7RTCrjAzc1Cm/EKi1Z4uXb36qsmSm+tSm9EVw8WP6roBB1hRlCP9ef9SD9S7vJBQZYIaA 2AZjYTC0dxRsLTzsjON37P4G3su0We61tqzW+OaIRIUsSz1DCfOmXjb0zINrtI9PX8YgmsGp1Dl7+ 8aaiRKG7pvhghy14FD70k3FNaZW4c3xgUnGKEhejl8vhz+k4Wvzt55CSKLY3OIJSbrE7SViQuBJz9 +dvcXvqY49HYLA3ak/5AjcgPWgc9KNgn+DjXgLonsbOIWovszXgTWkv/419NfkTPweGsc4m45;
Received: from h-178-174-130-130.a498.priv.bahnhof.se ([178.174.130.130]:38438 helo=frallan) by uggla.sjd.se with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from <simon@josefsson.org>) id 1wD1YT-004KM8-LL; Wed, 15 Apr 2026 14:49:25 +0000
From: Simon Josefsson <simon@josefsson.org>
To: Peter Gutmann <pgut001=40cs.auckland.ac.nz@dmarc.ietf.org>
In-Reply-To: <SYCPR01MB36614131C8ED5549B6582181EE222@SYCPR01MB3661.ausprd01.prod.outlook.com> (Peter Gutmann's message of "Wed, 15 Apr 2026 14:10:25 +0000")
References: <16CF0FDA-7263-461A-9F2B-D37DBEAF5DD9@sn3rd.com> <25c8d414-e4c8-455b-bd64-28132615ba75@cs.tcd.ie> <68f49a81-dd2c-4bea-896a-87da3e6aff68@tu-dresden.de> <CAMjbhoWwvfkfScpbf4-5PBzk__qb+6M4ZzAOba64kk9aXBba5g@mail.gmail.com> <d47a34ab-7fb9-4687-84aa-a5fa6bcf6a6c@tu-dresden.de> <2971d01a-89e3-43d3-a01d-b9c17b178763@amongbytes.com> <692bb582-ab7e-4d6b-aa75-ac5d93228bb2@tu-dresden.de> <DS4PPFA08475C7DBE27468E40C672197481C1242@DS4PPFA08475C7D.namprd11.prod.outlook.com> <LV0PR21MB6623B48B1F3A05D745F5A79D8C242@LV0PR21MB6623.namprd21.prod.outlook.com> <ad0svakv_WUM3btz@chardros.imrryr.org> <CAF8qwaBU_YHWX2MsWeeaOJ8sutR1wMozvbiTJF5kyvTE8YjWWA@mail.gmail.com> <CACsn0c=GDta824UF7uJ3nw_4U_rT=XhYOGHRemMWa+2AdbsiAg@mail.gmail.com> <3a16c7c4-345e-48ce-af70-a3bf503c8caf@app.fastmail.com> <CACf5n7_0hdeHJXXucva9pb=+pjhcgveHRpjA8XAcXB3LsYUvaw@mail.gmail.com> <CAFpG3gcC+UfO7E=ADGhwr2En5PwipZiq_r6_RdqvmT-5nnh2jw@mail.gmail.com> <d69ba150-0257-4e64-9abb-9229d03a03a6@app.fastmail.com> <87a4v42urw.fsf@josefsson.org> <SYCPR01MB36614131C8ED5549B6582181EE222@SYCPR01MB3661.ausprd01.prod.outlook.com>
OpenPGP: id=B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE; url=https://josefsson.org/key-20190320.txt
X-Hashcash: 1:23:260415:simon=40josefsson.org@dmarc.ietf.org::ZtYS+cVShAVX+1EI:4Ymu
X-Hashcash: 1:23:260415:tls@ietf.org::efdl+noYV09EzVYN:DfuH
X-Hashcash: 1:23:260415:filippo@ml.filippo.io::c2xAVQR/15d2jI79:9ppq
X-Hashcash: 1:23:260415:pgut001=40cs.auckland.ac.nz@dmarc.ietf.org::EgEnQupeglj3XDqF:nGsX
Date: Wed, 15 Apr 2026 16:49:39 +0200
Message-ID: <87se8w1doc.fsf@josefsson.org>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Message-ID-Hash: 2NLCPKC5RNB55TLXYMI7KEJIOTXNJMVG
X-Message-ID-Hash: 2NLCPKC5RNB55TLXYMI7KEJIOTXNJMVG
X-MailFrom: simon@josefsson.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "tls@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Composite ML-DSA
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/yONdhBYMOsu0jQZBbdXeVTRv6xo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Peter Gutmann <pgut001=40cs.auckland.ac.nz@dmarc.ietf.org> writes:

> If your protocol allows a man-in-the-middle attack, it's a real
> pearl-clutcher.

TLS 1.3 deprecated unauthenticated uses of TLS.  Thus I believe there is
wide support for the notion that server authentication provides value,
even to the point of deprecating alternatives.

> Hint: Some years ago many major sites (Apple, Amazon, eBay, HP, PayPal,
> Twitter, and many more) were using keys as weak as 384 bits for DKIM signing.
> One third of all DKIM-using domains were using keys so weak a dedicated
> individual could have broken them.  Despite the fact that the protocol, or at
> least the way it was used, allowed a REALLY bad attack, no-one did.

t-systems.nl uses a 384-bit RSA DKIM key even today, and didn't consider
it a problem when reported to them.

The reason few attacks DKIM is because there is so little to gain.

If someone knows a way to do a man-in-the-middle attack between Chrome
and google.com on some common user platform, I'm sure people would be
more interested than a DKIM attack.  There is a reason google.com or
t-systems.nl doesn't use a 384-bit RSA key for HTTPS.

/Simon