[DNSOP] Re: PQ DNSSEC?
Loganaden Velvindron <[email protected]> Wed, 29 Jul 2026 14:19:27 +0400
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <CAOp4FwTC2LYxqTz+yS8E9-R=FDyPsYJWXGqepsyqVffcWdv3Rg@mail.gmail.com> |
--===============1471070095655171495== Content-Type: multipart/alternative; boundary="000000000000f589ef0657bd4a62" --000000000000f589ef0657bd4a62 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable I think there is now a case for more diversity. On Fri, 24 Jul 2026, 13:49 Sophie Schmieg, <sschmieg=3D [email protected]> wrote: > In particular, it is hard to overstate the confidence gap cryptographers > have between the lattice based schemes (sans HAWK) and the rest of PQ > signature schemes (including HAWK). Pretty much any path to PQC DNSSEC > before 2030 requires the use of ML-DSA in order to be secure, and any hop= e > of having a solution before 2035 requires ML-DSA or FN-DSA, assuming > SLH-DSA or FAEST are out of the question. Code based cryptography arguabl= y > comes somewhat close in confidence, but that family does not currently ha= ve > any signature candidates. Unfortunately, this confidence is based on > decades of existing research, and while the other schemes currently > evaluated by NIST are interesting, we are at least a decade out from bein= g > able to trust them. > > On Fri, Jul 24, 2026 at 5:08=E2=80=AFAM Bas Westerbaan <bas=3D > [email protected]> wrote: > >> >> >> On Mon, Jul 20, 2026 at 2:52=E2=80=AFAM Watson Ladd <[email protected]= om> >> wrote: >> >>> Since singing is designed to be offline, and verification doesn't >>> actually matter, and size does, SQISign is the obvious choice. We know >>> verification doesn't matter given people regularly turn it off rather >>> than fail closed when verification is failing. >>> >> >> Yesterday a new attack against SQIsign was published [1], and it was >> acknowledged by the SQIsign designers [2]. It doesn't break SQIsign >> completely, but it looks like they'll have to change parameters. It'll t= ake >> some time to figure out by how much. This attack is not a surprise: SQIs= ign >> and the other appealing signature schemes in the on-ramp competition jus= t >> need more time for proper evaluation. >> >> Best, >> >> Bas >> >> >> [1] https://eprint.iacr.org/2026/1486 >> [2] >> https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9= _etUqkBwAJ >> _______________________________________________ >> DNSOP mailing list -- [email protected] >> To unsubscribe send an email to [email protected] >> > > > -- > > Sophie Schmieg | Information Security Engineer | ISE Crypto | > [email protected] > > _______________________________________________ > DNSOP mailing list -- [email protected] > To unsubscribe send an email to [email protected] > --000000000000f589ef0657bd4a62 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">I think there is now a case for more diversity.=C2=A0<div= dir=3D"auto"><br></div><div dir=3D"auto"><br></div></div><br><div class=3D= "gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">O= n Fri, 24 Jul 2026, 13:49 Sophie Schmieg, <sschmieg=3D<a href=3D"mailto:= [email protected]">[email protected]</a>> wrote:<br>= </div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-l= eft:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">In particular, it is = hard to overstate the confidence gap cryptographers have between the lattic= e based schemes (sans HAWK) and the rest of PQ signature schemes (including= HAWK). Pretty much any path to PQC DNSSEC before 2030 requires the use of = ML-DSA in order to be secure, and any hope of having a solution before 2035= requires ML-DSA or FN-DSA, assuming SLH-DSA or FAEST are out of the questi= on. Code based cryptography arguably comes somewhat close in confidence, bu= t that family does not currently have any signature candidates. Unfortunate= ly, this confidence is based on decades of existing research, and while the= other schemes currently evaluated by NIST are interesting, we are at least= a decade out from being able to trust them.</div><br><div class=3D"gmail_q= uote"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Jul 24, 2026 at 5:08=E2= =80=AFAM Bas Westerbaan <bas=3D<a href=3D"mailto:40cloudflare.com@dmarc.= ietf.org" target=3D"_blank" rel=3D"noreferrer">[email protected].= org</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"marg= in:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1e= x"><div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quot= e"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Jul 20, 2026 at 2:52=E2=80= =AFAM Watson Ladd <<a href=3D"mailto:[email protected]" target=3D"_b= lank" rel=3D"noreferrer">[email protected]</a>> wrote:<br></div><blo= ckquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left= :1px solid rgb(204,204,204);padding-left:1ex">Since singing is designed to = be offline, and verification doesn't<br> actually matter, and size does, SQISign is the obvious choice. We know<br> verification doesn't matter given people regularly turn it off rather<b= r> than fail closed when verification is failing.<br></blockquote><div><br></d= iv><div>Yesterday a new attack against SQIsign was published [1], and it wa= s acknowledged by the SQIsign designers [2]. It doesn't break SQIsign c= ompletely, but it looks like they'll have to change parameters. It'= ll take some time to figure out by how much. This attack is not a surprise:= SQIsign and the other appealing signature schemes in the on-ramp competiti= on just need more time for proper evaluation.</div><div><br></div><div>Best= ,</div><div><br></div><div>=C2=A0Bas</div><div><br></div><div><br></div><di= v>[1]=C2=A0<a href=3D"https://eprint.iacr.org/2026/1486" target=3D"_blank" = rel=3D"noreferrer">https://eprint.iacr.org/2026/1486</a>=C2=A0</div><div>[2= ]=C2=A0<a href=3D"https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/T= VIAOVbYP1w/m/K9_etUqkBwAJ" target=3D"_blank" rel=3D"noreferrer">https://gro= ups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_etUqkBwAJ</a>= </div></div></div> _______________________________________________<br> DNSOP mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank" r= el=3D"noreferrer">[email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" tar= get=3D"_blank" rel=3D"noreferrer">[email protected]</a><br> </blockquote></div><div><br clear=3D"all"></div><div><br></div><span class= =3D"gmail_signature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_s= ignature"><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div= ><div dir=3D"ltr"><div><div dir=3D"ltr"><div style=3D"line-height:1.5em;pad= ding-top:10px;margin-top:10px;color:rgb(85,85,85);font-family:sans-serif;fo= nt-size:small"><span style=3D"border-width:2px 0px 0px;border-style:solid;b= order-color:rgb(213,15,37);padding-top:2px;margin-top:2px"><br>Sophie Schmi= eg=C2=A0|</span><span style=3D"border-width:2px 0px 0px;border-style:solid;= border-color:rgb(51,105,232);padding-top:2px;margin-top:2px">=C2=A0Informat= ion Security Engineer=C2=A0|</span><span style=3D"border-width:2px 0px 0px;= border-style:solid;border-color:rgb(0,153,57);padding-top:2px;margin-top:2p= x">=C2=A0ISE Crypto=C2=A0|</span><span style=3D"border-width:2px 0px 0px;bo= rder-style:solid;border-color:rgb(238,178,17);padding-top:2px;margin-top:2p= x">=C2=A0<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"no= referrer">[email protected]</a></span></div><div><span style=3D"border-wi= dth:2px 0px 0px;border-style:solid;border-color:rgb(238,178,17);padding-top= :2px;margin-top:2px"><br></span></div><span style=3D"color:rgb(0,0,0);font-= family:"Times New Roman";font-size:medium"></span></div></div></d= iv></div></div></div></div></div></div></div> _______________________________________________<br> DNSOP mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank" r= el=3D"noreferrer">[email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" tar= get=3D"_blank" rel=3D"noreferrer">[email protected]</a><br> </blockquote></div> --000000000000f589ef0657bd4a62-- --===============1471070095655171495== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK --===============1471070095655171495==--