[openpgp] Re: PQC: ML-DSA only (non-composite) signatu re

Falko Strenzke <[email protected]>
Newsgroups gmane.ietf.openpgp
Organization MTG AG
Message-ID <[email protected]>
Am 25.06.25 um 10:20 schrieb Simo Sorce:
> On Mon, 2025-06-23 at 11:54 -0400, Daniel Kahn Gillmor wrote:
>> On Mon 2025-06-23 07:23:57 +0200, Falko Strenzke wrote:
>>> No such mechanism is necessary or makes sense at all. If the signer can
>>> tell the verifier what is a secure combination of signature algorithms,
>>> a malicious signer will specify a set of algorithms for which they can
>>> forge the signature. Or from a different perspective: how should the
>>> specification of the secure signature combinations itself be
>>> authenticated, as it is required prior to signature verification? Such a
>>> mechanism would be a severe security vulnerability.
>>>
>>> I have seen this erroneous line of argument often during the
>>> multi-algorithm signature discussions. In fact, the verifier's policy
>>> has to require at least one signature algorithm that at verification
>>> time is secure. There is no alternative to that.
>> For the record, I agree with Falko on this.  This kind of complexity is
>> probably dangerous, and seems unlikely to be useful. OpenPGP is simpler
>> and clearer to application developers and implementers alike when one
>> acceptable OpenPGP signature from any acceptable signer is sufficient
>> for a message verification to succeed.
>>
>> Doing anything more sophisticated than that (even if you try to avoid
>> tricky multilateral negotiations between signers and verifiers) seems
>> likely to push unmanageable complexity to the users of the standard.
>>
>> See the discussion at
>> https://gitlab.com/dkg/openpgp-stateless-cli/-/issues/104 for a
>> similar/related situation.
> While I agree I do not see how people go from this to the idea this
> means composed signatures are required and do not consider those also
> too complex.
>
> Just put two pure signatures on a message and the client will decide
> which one it trusts. If ML-DSA gets broken clients will stop trusting
> it and verify only the pure classic one.
Actually that was the initial proposal of the "working group outsiders" 
among the draft authors, but we soon learned from the community that 
parallel signatures are or were at that point not supported well enough 
in clients to take that approach. The preference for allowing only fixed 
algorithm combinations also played a role as far as I remember.
>
> For encryption there is an inherent need to do hybrid algorithms
> because there is an ongoing need to protect content that is out of your
> hands once it is transmitted, but signatures are checked at specific
> points in time, can always be rechecked and require no hybridization,
> because once broken the broken part is effectively useless.
I agree in principle. It is verifier who has to set up the verification 
policy and update it to counter emerging threats. Nevertheless there is 
an advantage in composite signatures in that they prevent the silent 
removal of one of the signatures by a malicious party. I fully agree 
that this is not a security problem. But can lead to reduced 
availability, as at a later point in time the message might rendered 
unverifiable due to the stripped-off signature.
>
> Hybrid/composite signatures just make everything more complicated for a
> minuscule gain, which is to "protect" content for a little amount of
> time while people update their client to stop trusting the broken
> signature type. I do not think the added complexity is worth it at all.

I think it is difficult to come to a clear verdict whether the 
complexity is worth the gain. For software pure implementations, which I 
assume to be in the far majority in the case of OpenPGP, the added 
complexity is approximately to make one additional call to a key 
generation, signing, and verification function. As the main gain I would 
see that a policy for long-term secure signatures becomes a bit easier 
to enforce by requiring ML-DSA-composites.

Falko

-- 

*MTG AG*
Dr. Falko Strenzke

Phone: +49 6151 8000 24
E-Mail: [email protected]
Web: mtg.de <https://www.mtg.de>

------------------------------------------------------------------------

MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany
Commercial register: HRB 8901
Register Court: Amtsgericht Darmstadt
Management Board: Jürgen Ruf (CEO), Tamer Kemeröz
Chairman of the Supervisory Board: Dr. Thomas Milde

This email may contain confidential and/or privileged information. If 
you are not the correct recipient or have received this email in error,
please inform the sender immediately and delete this email.Unauthorised 
copying or distribution of this email is not permitted.

Data protection information: Privacy policy 
<https://www.mtg.de/en/privacy-policy>

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/pkcs7-signature, 4.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.