[DNSOP] Re: PQ DNSSEC?
Bas Westerbaan <[email protected]> Fri, 24 Jul 2026 05:07:44 +0200
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <CAMjbhoV+tC1Mbfm=VjcRuz7g771mUoPpFgCNRsKrDMv1SPP4WA@mail.gmail.com> |
--===============7159326164465976018== Content-Type: multipart/alternative; boundary="000000000000cde0f3065752ad8f" --000000000000cde0f3065752ad8f Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Mon, Jul 20, 2026 at 2:52=E2=80=AFAM Watson Ladd <[email protected]>= wrote: > Since singing is designed to be offline, and verification doesn't > actually matter, and size does, SQISign is the obvious choice. We know > verification doesn't matter given people regularly turn it off rather > than fail closed when verification is failing. > Yesterday a new attack against SQIsign was published [1], and it was acknowledged by the SQIsign designers [2]. It doesn't break SQIsign completely, but it looks like they'll have to change parameters. It'll take some time to figure out by how much. This attack is not a surprise: SQIsign and the other appealing signature schemes in the on-ramp competition just need more time for proper evaluation. Best, Bas [1] https://eprint.iacr.org/2026/1486 [2] https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_et= UqkBwAJ --000000000000cde0f3065752ad8f Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Jul 20,= 2026 at 2:52=E2=80=AFAM Watson Ladd <<a href=3D"mailto:watsonbladd@gmai= l.com">[email protected]</a>> wrote:<br></div><blockquote class=3D"g= mail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204= ,204,204);padding-left:1ex">Since singing is designed to be offline, and ve= rification doesn't<br> actually matter, and size does, SQISign is the obvious choice. We know<br> verification doesn't matter given people regularly turn it off rather<b= r> than fail closed when verification is failing.<br></blockquote><div><br></d= iv><div>Yesterday a new attack against SQIsign was published [1], and it wa= s acknowledged by the SQIsign designers [2]. It doesn't break SQIsign c= ompletely, but it looks like they'll have to change parameters. It'= ll take some time to figure out by how much. This attack is not a surprise:= SQIsign and the other appealing signature schemes in the on-ramp competiti= on just need more time for proper evaluation.</div><div><br></div><div>Best= ,</div><div><br></div><div>=C2=A0Bas</div><div><br></div><div><br></div><di= v>[1]=C2=A0<a href=3D"https://eprint.iacr.org/2026/1486">https://eprint.iac= r.org/2026/1486</a>=C2=A0</div><div>[2]=C2=A0<a href=3D"https://groups.goog= le.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_etUqkBwAJ">https://gr= oups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_etUqkBwAJ</a= ></div></div></div> --000000000000cde0f3065752ad8f-- --===============7159326164465976018== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK --===============7159326164465976018==--