[DNSOP] Re: PQ DNSSEC?

Sophie Schmieg <[email protected]> Fri, 24 Jul 2026 11:48:02 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <CAEEbLAY9v0-DgtvYCMXeyfECrrjzZUeQVGxB7mzJ9mb94-3R8Q@mail.gmail.com>
--===============7766813632101173180==
Content-Type: multipart/alternative; boundary="0000000000006fee76065758452b"

--0000000000006fee76065758452b
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

In particular, it is hard to overstate the confidence gap cryptographers
have between the lattice based schemes (sans HAWK) and the rest of PQ
signature schemes (including HAWK). Pretty much any path to PQC DNSSEC
before 2030 requires the use of ML-DSA in order to be secure, and any hope
of having a solution before 2035 requires ML-DSA or FN-DSA, assuming
SLH-DSA or FAEST are out of the question. Code based cryptography arguably
comes somewhat close in confidence, but that family does not currently have
any signature candidates. Unfortunately, this confidence is based on
decades of existing research, and while the other schemes currently
evaluated by NIST are interesting, we are at least a decade out from being
able to trust them.

On Fri, Jul 24, 2026 at 5:08=E2=80=AFAM Bas Westerbaan <bas=3D
[email protected]> wrote:

>
>
> On Mon, Jul 20, 2026 at 2:52=E2=80=AFAM Watson Ladd <[email protected]=
m> wrote:
>
>> Since singing is designed to be offline, and verification doesn't
>> actually matter, and size does, SQISign is the obvious choice. We know
>> verification doesn't matter given people regularly turn it off rather
>> than fail closed when verification is failing.
>>
>
> Yesterday a new attack against SQIsign was published [1], and it was
> acknowledged by the SQIsign designers [2]. It doesn't break SQIsign
> completely, but it looks like they'll have to change parameters. It'll ta=
ke
> some time to figure out by how much. This attack is not a surprise: SQIsi=
gn
> and the other appealing signature schemes in the on-ramp competition just
> need more time for proper evaluation.
>
> Best,
>
>  Bas
>
>
> [1] https://eprint.iacr.org/2026/1486
> [2]
> https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_=
etUqkBwAJ
> _______________________________________________
> DNSOP mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>


--=20

Sophie Schmieg | Information Security Engineer | ISE Crypto |
[email protected]

--0000000000006fee76065758452b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">In particular, it is hard to overstate the confidence gap =
cryptographers have between the lattice based schemes (sans HAWK) and the r=
est of PQ signature schemes (including HAWK). Pretty much any path to PQC D=
NSSEC before 2030 requires the use of ML-DSA in order to be secure, and any=
 hope of having a solution before 2035 requires ML-DSA or FN-DSA, assuming =
SLH-DSA or FAEST are out of the question. Code based cryptography arguably =
comes somewhat close in confidence, but that family does not currently have=
 any signature candidates. Unfortunately, this confidence is based on decad=
es of existing research, and while the other schemes currently evaluated by=
 NIST are interesting, we are at least a decade out from being able to trus=
t them.</div><br><div class=3D"gmail_quote gmail_quote_container"><div dir=
=3D"ltr" class=3D"gmail_attr">On Fri, Jul 24, 2026 at 5:08=E2=80=AFAM Bas W=
esterbaan &lt;bas=3D<a href=3D"mailto:[email protected]">40cl=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gm=
ail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,=
204,204);padding-left:1ex"><div dir=3D"ltr"><div dir=3D"ltr"><br></div><br>=
<div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Ju=
l 20, 2026 at 2:52=E2=80=AFAM Watson Ladd &lt;<a href=3D"mailto:watsonbladd=
@gmail.com" target=3D"_blank">[email protected]</a>&gt; wrote:<br></div=
><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border=
-left:1px solid rgb(204,204,204);padding-left:1ex">Since singing is designe=
d to be offline, and verification doesn&#39;t<br>
actually matter, and size does, SQISign is the obvious choice. We know<br>
verification doesn&#39;t matter given people regularly turn it off rather<b=
r>
than fail closed when verification is failing.<br></blockquote><div><br></d=
iv><div>Yesterday a new attack against SQIsign was published [1], and it wa=
s acknowledged by the SQIsign designers [2]. It doesn&#39;t break SQIsign c=
ompletely, but it looks like they&#39;ll have to change parameters. It&#39;=
ll take some time to figure out by how much. This attack is not a surprise:=
 SQIsign and the other appealing signature schemes in the on-ramp competiti=
on just need more time for proper evaluation.</div><div><br></div><div>Best=
,</div><div><br></div><div>=C2=A0Bas</div><div><br></div><div><br></div><di=
v>[1]=C2=A0<a href=3D"https://eprint.iacr.org/2026/1486" target=3D"_blank">=
https://eprint.iacr.org/2026/1486</a>=C2=A0</div><div>[2]=C2=A0<a href=3D"h=
ttps://groups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_etU=
qkBwAJ" target=3D"_blank">https://groups.google.com/a/list.nist.gov/g/pqc-f=
orum/c/TVIAOVbYP1w/m/K9_etUqkBwAJ</a></div></div></div>
_______________________________________________<br>
DNSOP mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">d=
[email protected]</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]" tar=
get=3D"_blank">[email protected]</a><br>
</blockquote></div><div><br clear=3D"all"></div><div><br></div><span class=
=3D"gmail_signature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_s=
ignature"><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div=
><div dir=3D"ltr"><div><div dir=3D"ltr"><div style=3D"line-height:1.5em;pad=
ding-top:10px;margin-top:10px;color:rgb(85,85,85);font-family:sans-serif;fo=
nt-size:small"><span style=3D"border-width:2px 0px 0px;border-style:solid;b=
order-color:rgb(213,15,37);padding-top:2px;margin-top:2px"><br>Sophie Schmi=
eg=C2=A0|</span><span style=3D"border-width:2px 0px 0px;border-style:solid;=
border-color:rgb(51,105,232);padding-top:2px;margin-top:2px">=C2=A0Informat=
ion Security Engineer=C2=A0|</span><span style=3D"border-width:2px 0px 0px;=
border-style:solid;border-color:rgb(0,153,57);padding-top:2px;margin-top:2p=
x">=C2=A0ISE Crypto=C2=A0|</span><span style=3D"border-width:2px 0px 0px;bo=
rder-style:solid;border-color:rgb(238,178,17);padding-top:2px;margin-top:2p=
x">=C2=A0<a href=3D"mailto:[email protected]" target=3D"_blank">sschmieg@=
google.com</a></span></div><div><span style=3D"border-width:2px 0px 0px;bor=
der-style:solid;border-color:rgb(238,178,17);padding-top:2px;margin-top:2px=
"><br></span></div><span style=3D"color:rgb(0,0,0);font-family:&quot;Times =
New Roman&quot;;font-size:medium"></span></div></div></div></div></div></di=
v></div></div></div></div>

--0000000000006fee76065758452b--


--===============7766813632101173180==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp
bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg
dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK

--===============7766813632101173180==--