[openpgp] Re: PQC: ML-DSA only (non-composite) signatu re
Falko Strenzke <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Organization | MTG AG |
| Message-ID | <[email protected]> |
Am 25.06.25 um 10:20 schrieb Simo Sorce: > On Mon, 2025-06-23 at 11:54 -0400, Daniel Kahn Gillmor wrote: >> On Mon 2025-06-23 07:23:57 +0200, Falko Strenzke wrote: >>> No such mechanism is necessary or makes sense at all. If the signer can >>> tell the verifier what is a secure combination of signature algorithms, >>> a malicious signer will specify a set of algorithms for which they can >>> forge the signature. Or from a different perspective: how should the >>> specification of the secure signature combinations itself be >>> authenticated, as it is required prior to signature verification? Such a >>> mechanism would be a severe security vulnerability. >>> >>> I have seen this erroneous line of argument often during the >>> multi-algorithm signature discussions. In fact, the verifier's policy >>> has to require at least one signature algorithm that at verification >>> time is secure. There is no alternative to that. >> For the record, I agree with Falko on this. This kind of complexity is >> probably dangerous, and seems unlikely to be useful. OpenPGP is simpler >> and clearer to application developers and implementers alike when one >> acceptable OpenPGP signature from any acceptable signer is sufficient >> for a message verification to succeed. >> >> Doing anything more sophisticated than that (even if you try to avoid >> tricky multilateral negotiations between signers and verifiers) seems >> likely to push unmanageable complexity to the users of the standard. >> >> See the discussion at >> https://gitlab.com/dkg/openpgp-stateless-cli/-/issues/104 for a >> similar/related situation. > While I agree I do not see how people go from this to the idea this > means composed signatures are required and do not consider those also > too complex. > > Just put two pure signatures on a message and the client will decide > which one it trusts. If ML-DSA gets broken clients will stop trusting > it and verify only the pure classic one. Actually that was the initial proposal of the "working group outsiders" among the draft authors, but we soon learned from the community that parallel signatures are or were at that point not supported well enough in clients to take that approach. The preference for allowing only fixed algorithm combinations also played a role as far as I remember. > > For encryption there is an inherent need to do hybrid algorithms > because there is an ongoing need to protect content that is out of your > hands once it is transmitted, but signatures are checked at specific > points in time, can always be rechecked and require no hybridization, > because once broken the broken part is effectively useless. I agree in principle. It is verifier who has to set up the verification policy and update it to counter emerging threats. Nevertheless there is an advantage in composite signatures in that they prevent the silent removal of one of the signatures by a malicious party. I fully agree that this is not a security problem. But can lead to reduced availability, as at a later point in time the message might rendered unverifiable due to the stripped-off signature. > > Hybrid/composite signatures just make everything more complicated for a > minuscule gain, which is to "protect" content for a little amount of > time while people update their client to stop trusting the broken > signature type. I do not think the added complexity is worth it at all. I think it is difficult to come to a clear verdict whether the complexity is worth the gain. For software pure implementations, which I assume to be in the far majority in the case of OpenPGP, the added complexity is approximately to make one additional call to a key generation, signing, and verification function. As the main gain I would see that a policy for long-term secure signatures becomes a bit easier to enforce by requiring ML-DSA-composites. Falko -- *MTG AG* Dr. Falko Strenzke Phone: +49 6151 8000 24 E-Mail: [email protected] Web: mtg.de <https://www.mtg.de> ------------------------------------------------------------------------ MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany Commercial register: HRB 8901 Register Court: Amtsgericht Darmstadt Management Board: Jürgen Ruf (CEO), Tamer Kemeröz Chairman of the Supervisory Board: Dr. Thomas Milde This email may contain confidential and/or privileged information. If you are not the correct recipient or have received this email in error, please inform the sender immediately and delete this email.Unauthorised copying or distribution of this email is not permitted. Data protection information: Privacy policy <https://www.mtg.de/en/privacy-policy> _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
smime.p7s
(application/pkcs7-signature, 4.9 KB) - not displayed