[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2026-02-27)

Peter Gutmann <pgut001@cs.auckland.ac.nz> Sun, 22 February 2026 01:01 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C2002BB79BD3 for <tls@mail2.ietf.org>; Sat, 21 Feb 2026 17:01:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, LOTS_OF_MONEY=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cs.auckland.ac.nz
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dgg2tIFUAybX for <tls@mail2.ietf.org>; Sat, 21 Feb 2026 17:01:46 -0800 (PST)
Received: from SY8PR01CU002.outbound.protection.outlook.com (mail-australiaeastazon11020113.outbound.protection.outlook.com [52.101.150.113]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 2621EBB79BC0 for <tls@ietf.org>; Sat, 21 Feb 2026 17:01:45 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=NA7T9RkQAeY1AMp/odkmVkzRqaUCzqtS41jNjJNA4j7OdOeXIOsZmm0lpFtbLijV9vVG4LmvO/RonqYR5lY9p0eP47uYY0WunchaLXpjvIbx4M//TZIfn5lwMkfA9SZRA6evjcEBbkdDrGRmAu+pfPHRSCGA/Zr4G6NlqK7KgbqFl2EvB4Q+6x7qE2lCQTxE6glm+0b07DUqxPyfiDTq/SFkozNWBlRFExFAosP4kjk4EKKb+rP2faQ9+khsQ9X2YAHb9IXLP3bVQsNH0cOWShCWu/pH6pc3ILFJMhbVlWJ+P/LRTbQHjEvJbMzEBiHK1Ehp1Ztd45OEpN0zPfA5yw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gMKGaRAGkHvHfkmnDB5/Y/GM0zgeXL0EiUNgwSLIxe0=; b=C0SswHFr9VWjOtzsTAt6xBtm1UUMEqVGLKUVtlCDAKUvMgO18GSkXzKSUzoyomM7S2Ms2sNm78niiWxZ4ATNidtcstNb7ELKr1UoTDphcRldH8Hv9x8jXHU+V78KyWPAt68hjApoBiabHmpAO1/+l1G++A2Uvmz55MmDjCrgD3VHB+NZ8rFcNk9ZZ41mA8naPEUqLPgDtU8jYam0QZYRttf6K5IH3icXuHBQJFvvnJHaLEG15RNu23+0+81SzDWYRDaIREy60xzaoQot4wTME9YxTMAhFq/+K/rmrPB/b5uvZfsm7hhe8GOWQY8LD/pNxgATwu08i3hr6FR3qHTYXA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.auckland.ac.nz; dmarc=pass action=none header.from=cs.auckland.ac.nz; dkim=pass header.d=cs.auckland.ac.nz; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.auckland.ac.nz; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gMKGaRAGkHvHfkmnDB5/Y/GM0zgeXL0EiUNgwSLIxe0=; b=jA9TGiTyF0g8TxRd9eEqiksXp8U8t/4D0A1TALhpH7CjL0IS4gOD3eS5yaZ7xKePpOK4UwZOnqEhaFC4L3TBD9EwxOEA3upS9XiTgNNno13RXgJpBm0W/u2KKhIxRmDkcPtIddkyAJO+TDEKt+/bmVCLZC8xzKxG+LGtD6TI2sU0G1uWubp61yvXJtgWt2iDzzLz04mmoU28xd3yp2k4YvkF3L3Hsn8jMurn5A7mhJy3OfxvNtlpoYNEpw18S0MgSyvaakkX9IMJZFEJiTamxcvWKoX40TyjNmOr6RhWe1pAXQlUPbrKCv5e338+r40fbAtBe+ThXGKvYxw28+h7mQ==
Received: from MEAPR01MB3654.ausprd01.prod.outlook.com (2603:10c6:201:38::9) by SY9PR01MB10826.ausprd01.prod.outlook.com (2603:10c6:10:323::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9632.20; Sun, 22 Feb 2026 01:01:34 +0000
Received: from MEAPR01MB3654.ausprd01.prod.outlook.com ([fe80::e2ae:955b:18b7:3064]) by MEAPR01MB3654.ausprd01.prod.outlook.com ([fe80::e2ae:955b:18b7:3064%4]) with mapi id 15.20.9632.017; Sun, 22 Feb 2026 01:01:33 +0000
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Deirdre Connolly <durumcrustulum@gmail.com>, Izzy Grosof <izzy.grosof@northwestern.edu>
Thread-Topic: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2026-02-27)
Thread-Index: AQHcop0Sk+VOzK4tWE27SuiDkwMGt7WMFmEAgAHRGfA=
Date: Sun, 22 Feb 2026 01:01:33 +0000
Message-ID: <MEAPR01MB36544C8EDC087F6FDDC68CB4EE76A@MEAPR01MB3654.ausprd01.prod.outlook.com>
References: <MWHPR05MB3647B28767462F896A389FF59D68A@MWHPR05MB3647.namprd05.prod.outlook.com> <CAFR824z0CBKSi8P1o2Nr-h0pueNNN_SNitUVSg+W2VaB36JJHQ@mail.gmail.com>
In-Reply-To: <CAFR824z0CBKSi8P1o2Nr-h0pueNNN_SNitUVSg+W2VaB36JJHQ@mail.gmail.com>
Accept-Language: en-NZ, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.auckland.ac.nz;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MEAPR01MB3654:EE_|SY9PR01MB10826:EE_
x-ms-office365-filtering-correlation-id: c8b34d75-1cba-4f5b-b63c-08de71adebe7
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|366016|1800799024|376014|786006|38070700021;
x-microsoft-antispam-message-info: U1Zf/BBWbj/TSsi6UHne3sKZhiquLZA+CLFEdJM0fi51cl+3OLvTmtXmK/tYNdgLUKylUcZhuZWENnR/UptRMoQQeoMDa4WjjAcRa79O+HRq+RIT41zlOn6U0nwInfc2NFLtA7OhjbGuP8a/Z9SRGwFBUt16dDiNlVs4/GrbtPhwF+ENEDePQ2trCydXIrNvJPPZ+pH/H115hAo7HW43bWtj3YAONJMm86CIi8d2DMEE76hi/PtJOroPtMj9B6qjCQH56UAb35r+LC6cfJH04wnsy6rXjOQSJLQ3bpi7R8UcHwH0Qz5ZfVXb0TVm0Z4wexjQrCelJQFopXsOsoless6XBQE4CblCxIY8ooqcemU7TNzYWrIEebpLyJGdiTXBEFKpnSUazDKGYYNyJ643SjAfFMnWigmf9O1Q05FJIcihpJf5NC3o7T4ppR/CU2COTlrYI/s7dMAD1uj4jvkFboNc2Vvma/6UcWqQOgK+71aN/Bs2kd1HCDFGIbclFHYPyQjiD3PwtRcPTXOlanpzoaTplkOu3b5M7Snva5EJSWFlEipcAWvzBwbjLTUtwSe9FEiWU2zZHKijTiFCVd+oe71sd0cV4wGlZrVAeTZrASYricG0ZquLYdDdO8KoiOugNYMnfrEUWzny8iWghtNURw9n21CXMWdNpbrzDXgow9/N3CrfM+tX/zDjL0h9SoU0g9In2+E9R34qYsPQkSf5RUAab74cBm+b/CZRzvHI8hbsJC4mqKisHAvmt/kv2EOnq0ddtK+hppuuYJUJR39SJQOsTAEmLOiG6MxXXtZEHN5BKvwpT1n+UAa79fQN/OoBmk8Tpf/sRxxUGpnbwWS/mGEYUMLJgDYLVtBWc8QC/wKhBwIIDlm9Rv48BPZnYTFhU3SHY8qZHJDzdl4A/jyHNx/3JY9g1fodw14ufg6ZSBAjaiZ5h6UDtd6hYr7u53uFjv0n4tadqK96qR1vuFogh+9oGZmZuZJtX4sB3CcExKl1SMohDcWAyCEXa/Kay7QIt7Vq5L02IwQUMgt4nr/JcRJyBCTbg9ewIhQgtnztVEagupJ5wWwPUzD5Dp/srKrTGFfzKSiPMBQoQ6rlXoxJ2P07R1LEDb65XuRLGf5pClFVBMN+eMCsOPJJ9JVaSj925f5P/KS5eItGekpDgoSMP1CsQMbhisOG2USbyHEopr0MWaHewP1Grk1yICS+zBiJ3OYNQixcFpvF/lUH4cZEkeJZKjiqiL9Bkgyc6R3uh0ivAaDYj4NHs5jC3UAdiJGG3QBP61CIqwmXDdY3gzMuPttvs3URIzbwoGWopwHY9Q+IHCMmdUGtWbx68EBp8tv2K56DfD84a9T4VxDo/zLrC4eYLLyJn2AUucLUmTY8nb9lfUbHR1WUJVaeSPPkq1JFrleDImPo1Y2doPI1glWZ5LRzES+uvuhu7XRsTiH5Y3zvwvDszb97MN2SI5SZmtcQDZf7j0NzY6bDgcWmSOb2vDUyal2uG6cLbfR2RXB8JDOLggDUTZU6hfl6XQsGFzW6Ibv8J0iujaXrx5opeN/hN1escvto3auuc9FObMWXLAQnwIN5Dum0nfrUN+tAKnd7h4vc8qnYuvHZfdvqQdoKyp4av1YqNP1ZvzHiZob4od8=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MEAPR01MB3654.ausprd01.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(786006)(38070700021);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: gaKSx0Gm5aPOPqWxre/LE49vDFm13fy+q8iuF5v4dx06V4s/UA6qe53Zo6kbMz8ke+zfn3ZHSQXkNJNx6/VDWb0xYtDSYBp2uPe7edsA2Q2VMOIWv+dez+swercEUKhTRLwJIY3Qov/cH8UV6nkkhFxBKtm956Ab7UdRseCXPIiToMW9C4aNyvYuURPVzQAC3atSYVfq0jkfvcWqdXcNdHQPcQMSUuDNBRhW2827mZCnVQ97Pxu+nCEtkiTZ2k3oXoraibztNgceom/6KUfJn51InaVtVez7iDdE07hF/flIeqaZf0dhzyaABw9veXZX0vDocTz4kMuI6G+9wODbN4VpeIRkSD5abR+mXsRIglyREcIBsf8sc5Hb3keBnxR3w4xPVSI5bUvYVA3bTaOJTebPdfk1rj3QLtXc0h61FPwIWkmllny5xWHq/+vomFTaeUNAGs/YGrYHrInPDjqrxykK20qVU80Hqtlh+JiSIrcsL42gZAUF+PXUrc8EoBvyHapnTekBq9IJVZ6i0pcHvSKz58OlAyS23geraMadJ2/osRLka6XVO6Yysw5tORF3gra8GKiRfCVHPyp3MXQej9QXnzykZDk4NF0wAe3ThjvhfTVuSieTQsZFYBypLPoIwDDhiqBUozWv3pKHMfzjH+azKwv5DAyIm3+TOizwrhpxRucs4+7RVeVF/vabNC4yZeQ/V9bSh4r42xJaQABZvJ6JDYKrN+2MMIQO04zVxXeCokZThAzmcLXg+sboYRU8d4lLbqiK4zG2wyc/LqQ+czLaWbzbomh1R97luo60xkV68MC1U0Bd0X0oU7wNDH0ibd88DPST4soHcyY18b7xgKHjQOQWKdgsHAkv935qfCPO/xJ0kkzTMSDKT8WhmEBmMKeuZAzG2KuhV3t9osLMRH4sdp5j+RHKuCq+t0vTGI6NZroWmMT79+n2FvPR8mUSl7Pi+j4jaVxJp5lU9TzfC6qxijHitlsFu3y9YVXS5L5JqifPZeCF/jAN4NzVs9PjN+hT5Two/NlaaBnRqRzKiRpcZ1K/1VqDNqkiW+3ftHluW5C08JqBerNTTtef8l9Uqu4fIaqUTLHE2MkdqKbGnokxNWPKSWMgrjQgQP7OlJKC5vUO/fDAzQ1odfyyP23cBMigltVjj8TeYHP+38srevmSoa8/bIyCy6qIJRpNRmz0FY5WdaNrXQ5LDxPf5AEX9FuOwbhETo/9eKQu4MLWkzzSyLTuWY1IFjhOSlK+dHKuGS0TZ6joanzE4Hq83jEtZEA5RxbVY9pkzlH514ZmsY4kXD2AU1aqWxhQmjCD1+Li49LrZM2516+JZkvyr49wT/iKGuH6j4e04i3jr4cbb8DYKIPZ4K5aw2+16GbxcC4ey89wfNJQottVGQWVinj+WLkiksnmuB6Tu9up9siChzoO9U54wX+rolaFq5DOHmw1baUC7XRtysCsyz8n1dwK7gvAnFbng/K/vVkolA6Ty2GUorhxisjL/MzlzjcUozvHnZKbOMCy70m+29/Dyo0DSQuykHiZAWbcj2X/HVe9AHeQBTiXdnStI/LiUaELpnmIwyxuSt8cmDx0pJvCOxy8WI/GpTDnMnBYNSwKjbLYzcvDf2ZtvA5MD0lZA+f10tdeqL+LVewvNX+A6jMUYEjVC3T65nrOThPEMArK1aPXr2TdDmNwnWiy54/7mV7nQY0xExnDizOc7gV6cW2HNedw2g/NzUMjdWvmJ2U+QcjA8g==
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: cs.auckland.ac.nz
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MEAPR01MB3654.ausprd01.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: c8b34d75-1cba-4f5b-b63c-08de71adebe7
X-MS-Exchange-CrossTenant-originalarrivaltime: 22 Feb 2026 01:01:33.3793 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: d1b36e95-0d50-42e9-958f-b63fa906beaa
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: eIe7YF2SV3H7SoOBEFF3ow7oQWOtTPSxKN1Ldz6cvK/8HbfU8tNjVpgisyGiN8oGe2dkI7nnJuSU2lEotpG9vBrDlL6liEhBv2BuaGBuGo8=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SY9PR01MB10826
Message-ID-Hash: 6PMRTELTHBBDR34RNAWVZ7ZF6PCDRP4G
X-Message-ID-Hash: 6PMRTELTHBBDR34RNAWVZ7ZF6PCDRP4G
X-MailFrom: pgut001@cs.auckland.ac.nz
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Nadim Kobeissi <nadim@symbolic.software>, "TLS@ietf.org" <tls@ietf.org>, Rich Salz <rsalz=40akamai.com@dmarc.ietf.org>, Paul Wouters <paul=40nohats.ca@dmarc.ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-05 (Ends 2026-02-27)
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/NNcKZlRcF0gTe5vAShRqK3BBdOg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Deirdre Connolly <durumcrustulum@gmail.com> writes:

>This fails to mitigate Store Now Decrypt Later attacks which are considered a
>live threat to present TLS traffic

No they're not, or at least not based on any kind of rational thinking.  No-
one has ever demonstrated any kind of quantum physics experiment that
threatens DLP-based protocols, all we've got is data (if you want to call it
that) for imaginary devices like the German government (BSI) study that
estimated it'd take 100 days and EUR 4M in electricity to recover a single
2048-bit key using a physics experiment that doesn't exist and that no-one has
shown how to construct.  In 2017, the last year that I could find data for, 7
trillion TLS keys were negotiated.  Using the BSI figures for an imaginary
device that doesn't exist, you can recover 3.5 of those every year at a cost
of 15 million Euros, meaning you fall 7 trillion keys behind for every year of
operation.

Apologies for injecting actual data into the discussion.

If someone were to tell you something like the above outside of the field of
crypto and without including the magic word "quantum" in the discussion, you'd
be looking at them as if you expected a cuckoo to pop out of their forehead on
a spring.  At best, SNDL is the quantum equivalent of Roko's Basilisk.

Peter.