[DNSOP] Re: PQ DNSSEC?

Loganaden Velvindron <[email protected]> Wed, 29 Jul 2026 14:19:27 +0400
Newsgroups gmane.ietf.dnsop
Message-ID <CAOp4FwTC2LYxqTz+yS8E9-R=FDyPsYJWXGqepsyqVffcWdv3Rg@mail.gmail.com>
--===============1471070095655171495==
Content-Type: multipart/alternative; boundary="000000000000f589ef0657bd4a62"

--000000000000f589ef0657bd4a62
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

I think there is now a case for more diversity.



On Fri, 24 Jul 2026, 13:49 Sophie Schmieg, <sschmieg=3D
[email protected]> wrote:

> In particular, it is hard to overstate the confidence gap cryptographers
> have between the lattice based schemes (sans HAWK) and the rest of PQ
> signature schemes (including HAWK). Pretty much any path to PQC DNSSEC
> before 2030 requires the use of ML-DSA in order to be secure, and any hop=
e
> of having a solution before 2035 requires ML-DSA or FN-DSA, assuming
> SLH-DSA or FAEST are out of the question. Code based cryptography arguabl=
y
> comes somewhat close in confidence, but that family does not currently ha=
ve
> any signature candidates. Unfortunately, this confidence is based on
> decades of existing research, and while the other schemes currently
> evaluated by NIST are interesting, we are at least a decade out from bein=
g
> able to trust them.
>
> On Fri, Jul 24, 2026 at 5:08=E2=80=AFAM Bas Westerbaan <bas=3D
> [email protected]> wrote:
>
>>
>>
>> On Mon, Jul 20, 2026 at 2:52=E2=80=AFAM Watson Ladd <[email protected]=
om>
>> wrote:
>>
>>> Since singing is designed to be offline, and verification doesn't
>>> actually matter, and size does, SQISign is the obvious choice. We know
>>> verification doesn't matter given people regularly turn it off rather
>>> than fail closed when verification is failing.
>>>
>>
>> Yesterday a new attack against SQIsign was published [1], and it was
>> acknowledged by the SQIsign designers [2]. It doesn't break SQIsign
>> completely, but it looks like they'll have to change parameters. It'll t=
ake
>> some time to figure out by how much. This attack is not a surprise: SQIs=
ign
>> and the other appealing signature schemes in the on-ramp competition jus=
t
>> need more time for proper evaluation.
>>
>> Best,
>>
>>  Bas
>>
>>
>> [1] https://eprint.iacr.org/2026/1486
>> [2]
>> https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9=
_etUqkBwAJ
>> _______________________________________________
>> DNSOP mailing list -- [email protected]
>> To unsubscribe send an email to [email protected]
>>
>
>
> --
>
> Sophie Schmieg | Information Security Engineer | ISE Crypto |
> [email protected]
>
> _______________________________________________
> DNSOP mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

--000000000000f589ef0657bd4a62
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">I think there is now a case for more diversity.=C2=A0<div=
 dir=3D"auto"><br></div><div dir=3D"auto"><br></div></div><br><div class=3D=
"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">O=
n Fri, 24 Jul 2026, 13:49 Sophie Schmieg, &lt;sschmieg=3D<a href=3D"mailto:=
[email protected]">[email protected]</a>&gt; wrote:<br>=
</div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-l=
eft:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">In particular, it is =
hard to overstate the confidence gap cryptographers have between the lattic=
e based schemes (sans HAWK) and the rest of PQ signature schemes (including=
 HAWK). Pretty much any path to PQC DNSSEC before 2030 requires the use of =
ML-DSA in order to be secure, and any hope of having a solution before 2035=
 requires ML-DSA or FN-DSA, assuming SLH-DSA or FAEST are out of the questi=
on. Code based cryptography arguably comes somewhat close in confidence, bu=
t that family does not currently have any signature candidates. Unfortunate=
ly, this confidence is based on decades of existing research, and while the=
 other schemes currently evaluated by NIST are interesting, we are at least=
 a decade out from being able to trust them.</div><br><div class=3D"gmail_q=
uote"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Jul 24, 2026 at 5:08=E2=
=80=AFAM Bas Westerbaan &lt;bas=3D<a href=3D"mailto:40cloudflare.com@dmarc.=
ietf.org" target=3D"_blank" rel=3D"noreferrer">[email protected].=
org</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"marg=
in:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1e=
x"><div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quot=
e"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Jul 20, 2026 at 2:52=E2=80=
=AFAM Watson Ladd &lt;<a href=3D"mailto:[email protected]" target=3D"_b=
lank" rel=3D"noreferrer">[email protected]</a>&gt; wrote:<br></div><blo=
ckquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left=
:1px solid rgb(204,204,204);padding-left:1ex">Since singing is designed to =
be offline, and verification doesn&#39;t<br>
actually matter, and size does, SQISign is the obvious choice. We know<br>
verification doesn&#39;t matter given people regularly turn it off rather<b=
r>
than fail closed when verification is failing.<br></blockquote><div><br></d=
iv><div>Yesterday a new attack against SQIsign was published [1], and it wa=
s acknowledged by the SQIsign designers [2]. It doesn&#39;t break SQIsign c=
ompletely, but it looks like they&#39;ll have to change parameters. It&#39;=
ll take some time to figure out by how much. This attack is not a surprise:=
 SQIsign and the other appealing signature schemes in the on-ramp competiti=
on just need more time for proper evaluation.</div><div><br></div><div>Best=
,</div><div><br></div><div>=C2=A0Bas</div><div><br></div><div><br></div><di=
v>[1]=C2=A0<a href=3D"https://eprint.iacr.org/2026/1486" target=3D"_blank" =
rel=3D"noreferrer">https://eprint.iacr.org/2026/1486</a>=C2=A0</div><div>[2=
]=C2=A0<a href=3D"https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/T=
VIAOVbYP1w/m/K9_etUqkBwAJ" target=3D"_blank" rel=3D"noreferrer">https://gro=
ups.google.com/a/list.nist.gov/g/pqc-forum/c/TVIAOVbYP1w/m/K9_etUqkBwAJ</a>=
</div></div></div>
_______________________________________________<br>
DNSOP mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank" r=
el=3D"noreferrer">[email protected]</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]" tar=
get=3D"_blank" rel=3D"noreferrer">[email protected]</a><br>
</blockquote></div><div><br clear=3D"all"></div><div><br></div><span class=
=3D"gmail_signature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_s=
ignature"><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div=
><div dir=3D"ltr"><div><div dir=3D"ltr"><div style=3D"line-height:1.5em;pad=
ding-top:10px;margin-top:10px;color:rgb(85,85,85);font-family:sans-serif;fo=
nt-size:small"><span style=3D"border-width:2px 0px 0px;border-style:solid;b=
order-color:rgb(213,15,37);padding-top:2px;margin-top:2px"><br>Sophie Schmi=
eg=C2=A0|</span><span style=3D"border-width:2px 0px 0px;border-style:solid;=
border-color:rgb(51,105,232);padding-top:2px;margin-top:2px">=C2=A0Informat=
ion Security Engineer=C2=A0|</span><span style=3D"border-width:2px 0px 0px;=
border-style:solid;border-color:rgb(0,153,57);padding-top:2px;margin-top:2p=
x">=C2=A0ISE Crypto=C2=A0|</span><span style=3D"border-width:2px 0px 0px;bo=
rder-style:solid;border-color:rgb(238,178,17);padding-top:2px;margin-top:2p=
x">=C2=A0<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"no=
referrer">[email protected]</a></span></div><div><span style=3D"border-wi=
dth:2px 0px 0px;border-style:solid;border-color:rgb(238,178,17);padding-top=
:2px;margin-top:2px"><br></span></div><span style=3D"color:rgb(0,0,0);font-=
family:&quot;Times New Roman&quot;;font-size:medium"></span></div></div></d=
iv></div></div></div></div></div></div></div>
_______________________________________________<br>
DNSOP mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank" r=
el=3D"noreferrer">[email protected]</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]" tar=
get=3D"_blank" rel=3D"noreferrer">[email protected]</a><br>
</blockquote></div>

--000000000000f589ef0657bd4a62--


--===============1471070095655171495==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRE5TT1AgbWFp
bGluZyBsaXN0IC0tIGRuc29wQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg
dG8gZG5zb3AtbGVhdmVAaWV0Zi5vcmcK

--===============1471070095655171495==--