[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2026-02-27)

Deirdre Connolly <durumcrustulum@gmail.com> Sat, 28 February 2026 00:21 UTC

Return-Path: <neried7@gmail.com>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 67BD6C0114DC for <tls@mail2.ietf.org>; Fri, 27 Feb 2026 16:21:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.848
X-Spam-Level:
X-Spam-Status: No, score=-1.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lidQf8W3-7b2 for <tls@mail2.ietf.org>; Fri, 27 Feb 2026 16:21:58 -0800 (PST)
Received: from mail-qv1-xf30.google.com (mail-qv1-xf30.google.com [IPv6:2607:f8b0:4864:20::f30]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id EC726C0114D5 for <tls@ietf.org>; Fri, 27 Feb 2026 16:21:58 -0800 (PST)
Received: by mail-qv1-xf30.google.com with SMTP id 6a1803df08f44-899c97c5afeso18374296d6.1 for <tls@ietf.org>; Fri, 27 Feb 2026 16:21:58 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1772238118; cv=none; d=google.com; s=arc-20240605; b=F9y1EF5luGfBWN4tECGSw5gEsxTZAefP/EwOzS7Na9I0RocemUNHTF1HvLeZmiVzVa /nDoBeMrjyXpQ/ThtboVg0CeeB0+7Y0InTae27XTBqDuCfhJBppwmwy7eWX0WUw+ZwKJ Fya93dsR8v6pvn1maf8nQhydQDeRKFzTQkFxq5KTsHujo6m4y94MPXDDR3MDTcOFR6nx VC6i6x/L4SjEhAk25ECxyzov4WBAEFzAfPA9TcvxrcGB8iB3krDFJX8LgglfrjL3MLkJ nP+bkz1vmCRQaizn8/tbzEARXQKX0Z7hm476YGjb9omxydXQXNyLG5svMFreHhzaUjAD 29mw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=EhYEoIOVIW63H7QIiP0n4hzubqUD4o9cdAhMgws/zmo=; fh=eU+6bKvhtkKTqZoFgAX/tLrdQZoQGWrrGfITAnDT8IU=; b=L9EUdmIQMFpdBrtuIdeVW20iTAzu9K6sVSHUSwBpIFwprGH3zEZvpSfZeOwJ7GmWSl vm/C5SSPeffbfwXR5NqiMIortyuHf1lrQZT6MP8KwdSVhnyO4mvZ0cMyEJSQ3FyMAn27 e+0WoMhtsHxmyTCufznra8+t2X/wM84zJUXMYcXUJdFFIBCd4/h7Z2WTXqzhdPuoiRpp qyxvnf6mf1mJFvM73yyQ5VbBaZQDc24Nu8Uo1vmEOr84E0HiPhcsIYq17Tt3uyQgvgUG CxnqL4q97rDo4dRVT9VDY+g6S5Xx2Z0jzMnlHiFCj60VYPwgkSqfecZluAlrcvQVr+DM f2YA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1772238118; x=1772842918; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=EhYEoIOVIW63H7QIiP0n4hzubqUD4o9cdAhMgws/zmo=; b=V7TkQB3o3LKDu/11NHI7J5VCZ8SujzS3KsuSLipKbWj4EZ9i7TGiYD8yZOVk3YcQKT wqmcdKfiPfsMUNJ9bzHI4MlJJDIP6l+WfqxDho+N74LoLNn+WsPoEcXqH13SsQpiv9NU bL+G9Vb31Z6KGp7ix7j1+PN+Y4UbpE8hIe6lWCUO9pRi5mUYhuMxTN/rqbkVEseebRiD TXjAwcF/OZ+D7IT2c5cKVAKr0fgiiJZrZzBcWq9aQrRhMYkrVmm8DHCMLP0o/TkxUzLr OFWF4f/74cgmGmH+Y45LoMEY1uRmPZpV/hMj9tO8w0cZQCEUVGmStyjjb0RIUQQZajkm JgvA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772238118; x=1772842918; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=EhYEoIOVIW63H7QIiP0n4hzubqUD4o9cdAhMgws/zmo=; b=XXhCQTJH8grSgevRigV+sOpCQgQqNlUV2eORnnMm/ysnp9MrFZI6bN6zdre6VzeZCQ 3TK1xt2LqFZi4ZsTYd0Z3wTk0OiU5TYKhp3ydSXaKW1rniLcLw4aey4zSR/RizIEp7R4 wvZ9tXZnohwPx6abvh68hii/jHwnI0/lyhun2C2J5UzuH8o+IxTEvPm0KYEVGIt9coLU PFVRl42z/BunYXceAFgAuI9lEbLEQiOJUMU12ugzzi6G/ZkisCIUjHkYwmAKkJP2p5TG X38SZlCFVBzGMCCBuqVrFKH+ukBfRwyW4K3ea5m90tm6R7qyh8WwCBdTXJXbtTDkYKzg YZAA==
X-Gm-Message-State: AOJu0YwsQFcb27sVBf5vK4ijMlT8QsuY5qRxskz0fnlXU/0jc1bIb8qi LbcjtixN8rHzBFrWgNg8pETDs4J9axaVo7zzdxP3o2ksgNl09m4QqBf3L/7FUtY1zhBnP3G9zKf WPCI29Jmmk831fSAgguJImdiKPb9gDhPl/7hQeeI=
X-Gm-Gg: ATEYQzzW7GpUIaPZxl8MLiSGercYdlwHl0fJDSYeG76fBZdQiNcT1pXLxUYn+F4T1ih C8dmSSSofXjkbX3en2GLLLons8TnONrd5OoSeJ+EEvENpFIWf4Eg3e0FDLPDw8A4q45oO0xsLZZ a4q9+zbKKMwBMds24rmNzBlu65Fa9dG1HGW/cvZ49NU7XayXQkHZoZZkoB9QYJlJBxF+w1TYqu6 BbZjxyoro7CpEvutdvnyGagWpuhG8YOrqGwDFpbUr7rWRV6SVn+QVUbjXyDAGB00BHiYzWzJfHM J9zVFN6ublKi/u/NvJSRrefleEqz3nG/9ZMnNg==
X-Received: by 2002:a05:6214:29e4:b0:88a:2f90:b6f9 with SMTP id 6a1803df08f44-899d1dc0b21mr74062666d6.20.1772238118288; Fri, 27 Feb 2026 16:21:58 -0800 (PST)
MIME-Version: 1.0
References: <aaH7oSjfTR6KnmW8@LK-Perkele-VII2.locald> <05529422-A5E7-4C0E-B7DF-9C6A98923035@uni-wuppertal.de>
In-Reply-To: <05529422-A5E7-4C0E-B7DF-9C6A98923035@uni-wuppertal.de>
From: Deirdre Connolly <durumcrustulum@gmail.com>
Date: Fri, 27 Feb 2026 19:21:45 -0500
X-Gm-Features: AaiRm53HrPGPuQ7nxXVldYBjMPw5N1dHO6RkLzaOzcwcAmuANADia2w_PCspaTs
Message-ID: <CAFR824xshLCShUgXeJTpQU+aPZGADVc0soRDdb=m+caqHRJ89w@mail.gmail.com>
To: Tibor Jager <jager@uni-wuppertal.de>
Content-Type: multipart/alternative; boundary="0000000000007f7e58064bd75723"
Message-ID-Hash: 5WRMS74UJGPGNCKSCZ54ZDOWBFFLTXEP
X-Message-ID-Hash: 5WRMS74UJGPGNCKSCZ54ZDOWBFFLTXEP
X-MailFrom: neried7@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "TLS@ietf.org" <tls@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2026-02-27)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/ZfprzuC5lBhshQRm7QfmO0qf5Qk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

> In particular when the use of hybrid crypto comes with negligible
overhead, as for ML-KEM + ECC.

X25519 is almost twice as slow as MLKEM768 (
https://blog.cloudflare.com/pq-2025/#ml-kem-versus-x25519)  P-256 is about
the same

On Fri, Feb 27, 2026, 5:25 PM Tibor Jager <jager@uni-wuppertal.de> wrote:

>
>
> > Am 27.02.2026 um 21:16 schrieb Ilari Liusvaara <ilariliusvaara@welho.com
> >:
> > - There does not seem to be any evidence that ML-KEM is weak. I think
> >  that if ML-KEM gets badly broken, it will be for unforeseeable reasons
> >  (which is a risk for any cryptographic algorithm, including prime-
> >  field ECC).
>
> Except that for a hybrid mode, both ML-KEM and ECC must be broken
> simultaneously.
>
> I think it is unwise to rely *only* on ML-KEM (or any other scheme based
> on relatively new hardness assumptions), and currently do not support any
> draft that does not use hybrid cryptography. In particular when the use of
> hybrid crypto comes with negligible overhead, as for ML-KEM + ECC.
>
> For almost every broken cryptosystem there was a time when there seemed to
> be no evidence that it is weak. ML-KEM still needs to stand the test of
> time.
>
> Best regards,
> Tibor
> _______________________________________________
> TLS mailing list -- tls@ietf.org
> To unsubscribe send an email to tls-leave@ietf.org
>