[openpgp] Re: PQC: ML-DSA only (non-composite) signatu re

Falko Strenzke <[email protected]>
Newsgroups gmane.ietf.openpgp
Organization MTG AG
Message-ID <[email protected]>
Am 18.06.25 um 20:33 schrieb Daniel Kahn Gillmor:
> The fact that a single message might be signed by multiple keys isn't a
> use case specific to PQ(/T) at all (it is also related to novel digest
> algorithms, unknown signing certificates, and so on), and the general
> OpenPGP ecosystem has gotten better at handling multiply-signed messages
> since the wider adoption of the semantics of the Stateless OpenPGP
> interface.  That said, communicating semantics to the verifier that
> multiple signatures must be present to meet the desired security
> threshhold is something OpenPGP can't really do right now.

No such mechanism is necessary or makes sense at all. If the signer can 
tell the verifier what is a secure combination of signature algorithms, 
a malicious signer will specify a set of algorithms for which they can 
forge the signature. Or from a different perspective: how should the 
specification of the secure signature combinations itself be 
authenticated, as it is required prior to signature verification? Such a 
mechanism would be a severe security vulnerability.

I have seen this erroneous line of argument often during the 
multi-algorithm signature discussions. In fact, the verifier's policy 
has to require at least one signature algorithm that at verification 
time is secure. There is no alternative to that.

Falko

-- 

*MTG AG*
Dr. Falko Strenzke

Phone: +49 6151 8000 24
E-Mail: [email protected]
Web: mtg.de <https://www.mtg.de>

------------------------------------------------------------------------

MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany
Commercial register: HRB 8901
Register Court: Amtsgericht Darmstadt
Management Board: Jürgen Ruf (CEO), Tamer Kemeröz
Chairman of the Supervisory Board: Dr. Thomas Milde

This email may contain confidential and/or privileged information. If 
you are not the correct recipient or have received this email in error,
please inform the sender immediately and delete this email.Unauthorised 
copying or distribution of this email is not permitted.

Data protection information: Privacy policy 
<https://www.mtg.de/en/privacy-policy>

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/pkcs7-signature, 4.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.