[DNSOP] Re: PQ DNSSEC?

Bas Westerbaan <[email protected]> Fri, 24 Jul 2026 05:07:44 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <CAMjbhoV+tC1Mbfm=VjcRuz7g771mUoPpFgCNRsKrDMv1SPP4WA@mail.gmail.com>
--===============7159326164465976018==
Content-Type: multipart/alternative; boundary="000000000000cde0f3065752ad8f"

--000000000000cde0f3065752ad8f
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Mon, Jul 20, 2026 at 2:52=E2=80=AFAM Watson Ladd <[email protected]>=
 wrote:

> Since singing is designed to be offline, and verification doesn't
> actually matter, and size does, SQISign is the obvious choice. We know
> verification doesn't matter given people regularly turn it off rather
> than fail closed when verification is failing.
>

Yesterday a new attack against SQIsign was published [1], and it was
acknowledged by the SQIsign designers [2]. It doesn't break SQIsign
completely, but it looks like they'll have to change parameters. It'll take
some time to figure out by how much. This attack is not a surprise: SQIsign
and the other appealing signature schemes in the on-ramp competition just
need more time for proper evaluation.

Best,

 Bas


[1] https://eprint.iacr.org/2026/1486
[2]
https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_et=
UqkBwAJ

--000000000000cde0f3065752ad8f
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g=
mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Jul 20,=
 2026 at 2:52=E2=80=AFAM Watson Ladd &lt;<a href=3D"mailto:watsonbladd@gmai=
l.com">[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"g=
mail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204=
,204,204);padding-left:1ex">Since singing is designed to be offline, and ve=
rification doesn&#39;t<br>
actually matter, and size does, SQISign is the obvious choice. We know<br>
verification doesn&#39;t matter given people regularly turn it off rather<b=
r>
than fail closed when verification is failing.<br></blockquote><div><br></d=
iv><div>Yesterday a new attack against SQIsign was published [1], and it wa=
s acknowledged by the SQIsign designers [2]. It doesn&#39;t break SQIsign c=
ompletely, but it looks like they&#39;ll have to change parameters. It&#39;=
ll take some time to figure out by how much. This attack is not a surprise:=
 SQIsign and the other appealing signature schemes in the on-ramp competiti=
on just need more time for proper evaluation.</div><div><br></div><div>Best=
,</div><div><br></div><div>=C2=A0Bas</div><div><br></div><div><br></div><di=
v>[1]=C2=A0<a href=3D"https://eprint.iacr.org/2026/1486">https://eprint.iac=
r.org/2026/1486</a>=C2=A0</div><div>[2]=C2=A0<a href=3D"https://groups.goog=
le.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_etUqkBwAJ">https://gr=
oups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_etUqkBwAJ</a=
></div></div></div>

--000000000000cde0f3065752ad8f--


--===============7159326164465976018==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp
bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg
dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK

--===============7159326164465976018==--