[TLS] Re: Fwd: New Version Notification for draft-barnes-tls-this-could-have-been-an-email-00.txt

DA PIEVE Fabiana <Fabiana.DA-PIEVE@ec.europa.eu> Wed, 25 February 2026 16:43 UTC

Return-Path: <Fabiana.DA-PIEVE@ec.europa.eu>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E294FBE09EB1 for <tls@mail2.ietf.org>; Wed, 25 Feb 2026 08:43:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.298
X-Spam-Level:
X-Spam-Status: No, score=-4.298 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=ec.europa.eu
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id M5pyUkL9SHiR for <tls@mail2.ietf.org>; Wed, 25 Feb 2026 08:43:48 -0800 (PST)
Received: from out.mail.ec.europa.eu (out.mail.ec.europa.eu [147.67.249.4]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id A0EEDBE09EA7 for <tls@ietf.org>; Wed, 25 Feb 2026 08:43:47 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=s2601; d=ec.europa.eu; h=from:to:subject:date:message-id:content-type:mime-version; bh=Iv7ng9JdKfQIH8LrPqBJrbgtKCFiJkk+PJxNjNQ0rsA=; b=aayv+h83DO8q/t+7BvE0yJ0dJesm6OczYYHsdXJ7zazreB7E29uZ91tfLXEjC0 aMdq9UeLOV2Xx7e/+jfLRQTmb/elLXqUz0OJqpbTEWXrzQS0C041jAqjG3fhk6 UN4GPJS1GNzIM5p217GHf8p2QBvc0NhSqtps+XP5ohjkXMKXJiYAcT7QZogXY8 nY1vZW5aGvabKprzoR9SVDA9fMgmVKiuvzH3dLcCvs2RGovWlDXaY3PauEh8d1 I0UBVfBHJPTLy53MYrCw/uGO7mduTLyaB4bf6joKVgYZtQukd7eyU/uId8qI6l nSdJRiy0plj5A6+Gdsf8saDQDEA2Kc2A==
Received: from sp-exc-1703.welcome.ec.europa.eu (10.152.64.163) by sp-exc-ed112.rcnet.cec.eu.int (147.67.249.4) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.35; Wed, 25 Feb 2026 17:43:46 +0100
Received: from sp-exc-1704.welcome.ec.europa.eu (10.152.64.164) by sp-exc-1703.welcome.ec.europa.eu (10.152.64.163) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.37; Wed, 25 Feb 2026 17:24:06 +0100
Received: from sp-exc-1704.welcome.ec.europa.eu ([10.152.64.164]) by sp-exc-1704.welcome.ec.europa.eu ([10.152.64.164]) with mapi id 15.02.2562.037; Wed, 25 Feb 2026 17:24:06 +0100
From: DA PIEVE Fabiana <Fabiana.DA-PIEVE@ec.europa.eu>
To: "tls@ietf.org" <tls@ietf.org>
Thread-Topic: Re: [TLS] Re: Fwd: New Version Notification for draft-barnes-tls-this-could-have-been-an-email-00.txt
Thread-Index: AdymcwniLCPaByMDSj+gimeMjBSZQw==
Date: Wed, 25 Feb 2026 16:24:05 +0000
Message-ID: <dd4e3405ff1046e2851ebca0108aee2f@ec.europa.eu>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_6bd9ddd1-4d20-43f6-abfa-fc3c07406f94_ActionId=039a5816-f593-4eaa-9047-d372717303cd;MSIP_Label_6bd9ddd1-4d20-43f6-abfa-fc3c07406f94_ContentBits=0;MSIP_Label_6bd9ddd1-4d20-43f6-abfa-fc3c07406f94_Enabled=true;MSIP_Label_6bd9ddd1-4d20-43f6-abfa-fc3c07406f94_Method=Standard;MSIP_Label_6bd9ddd1-4d20-43f6-abfa-fc3c07406f94_Name=Commission Use;MSIP_Label_6bd9ddd1-4d20-43f6-abfa-fc3c07406f94_SetDate=2026-02-25T16:23:13Z;MSIP_Label_6bd9ddd1-4d20-43f6-abfa-fc3c07406f94_SiteId=b24c8b06-522c-46fe-9080-70926f8dddb1;MSIP_Label_6bd9ddd1-4d20-43f6-abfa-fc3c07406f94_Tag=10, 3, 0, 1;
x-originating-ip: [10.152.64.253]
Content-Type: multipart/related; boundary="_004_dd4e3405ff1046e2851ebca0108aee2feceuropaeu_"; type="multipart/alternative"
MIME-Version: 1.0
Message-ID-Hash: AVRCOMQM64S7SOUHJIUTADPEXEO6X2WH
X-Message-ID-Hash: AVRCOMQM64S7SOUHJIUTADPEXEO6X2WH
X-MailFrom: Fabiana.DA-PIEVE@ec.europa.eu
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Fwd: New Version Notification for draft-barnes-tls-this-could-have-been-an-email-00.txt
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/HOzfpUCJiCXTcoEvYwLxayS7-gc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

In my personal capacity, I have to say that in all this discussion it is not clear to me yet the main issue - the reason why we would go for a path that is not based on a common good sense, by removing the assurance of security given by “old” good crypto. This adds up to the fact that the cost of keeping it is actually cheap, and to the fact that an outstanding work has been done already to deploy hybrid ML-KEM in TLS.  Hybrid ML-KEM is such a cheap way to reduce risks. So, overall, I still cannot crystallize in my head what is the advantage in security and costs in throwing away ECC and how to reconcile this with what is pushed in my own part of the world. Not sure what would be the advantage in fragmenting things now. I would like to invite all EU researchers or anyway all those with whom I am contact to write to me to help me increasing my understanding of the exceptional need for all this, and eventually share their technical concerns, to see if they overlap with mine, in case you would have time and you would be willing to do so. I thank everybody here for the discussion.

Fabiana Da Pieve
Program Manager

[cid:image001.gif@01DCA67B.88EC0670]

European Commission
DG Communications Networks, Content and Technology
Unit C4 – Emerging & Disruptive Technologies