[openpgp] Re: PQC: ML-DSA only (non-composite) signatu re

Daniel Kahn Gillmor <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On Mon 2025-06-23 07:23:57 +0200, Falko Strenzke wrote:
> No such mechanism is necessary or makes sense at all. If the signer can 
> tell the verifier what is a secure combination of signature algorithms, 
> a malicious signer will specify a set of algorithms for which they can 
> forge the signature. Or from a different perspective: how should the 
> specification of the secure signature combinations itself be 
> authenticated, as it is required prior to signature verification? Such a 
> mechanism would be a severe security vulnerability.
>
> I have seen this erroneous line of argument often during the 
> multi-algorithm signature discussions. In fact, the verifier's policy 
> has to require at least one signature algorithm that at verification 
> time is secure. There is no alternative to that.

For the record, I agree with Falko on this.  This kind of complexity is
probably dangerous, and seems unlikely to be useful. OpenPGP is simpler
and clearer to application developers and implementers alike when one
acceptable OpenPGP signature from any acceptable signer is sufficient
for a message verification to succeed.

Doing anything more sophisticated than that (even if you try to avoid
tricky multilateral negotiations between signers and verifiers) seems
likely to push unmanageable complexity to the users of the standard.

See the discussion at
https://gitlab.com/dkg/openpgp-stateless-cli/-/issues/104 for a
similar/related situation.

    --dkg

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.