[saag] Re: Fragmentation, crypto drafts, and a way forwa rd

Stephen Farrell <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Hiya,

On 23/10/2025 03:00, Paul Hoffman wrote:
> Haven't we been here before? Many times in the past 30 years?

I don't think so. The closest I can recall was back when someone
turned up wanting to add about 70 TLS ciphersuites, being the
cross-product of ECC with everything else, which IIRC got laughed
at back then.

The number of new algorithm IDs/code-points we're adding in all the
PQ stuff is getting silly. [1] adds 18, [2] adds 12, between [3,4]
we'd be adding 17 code-points in a one-octet range. And the same I
guess must be happening in other WGs. Seems bad for interop to me
and bad for security with all the likely unused code.

And then there's the "it can't be hybrid"/"it must be hybrid" stuff
from NIST and other regulators.

And then there's the fact that we don't really know how all this will
play out with PKI.

I won't go on and on, but I could.

We're doing it wrong.

Cheers,
S.

PS: To be clear: I'm not saying e.g. those wanting [4] are bad actors
or doing some kind of process end-run. I'm saying we're collectively
getting this wrong.

[1] https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-sigs/
[2] https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-kem/
[3] https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/
[4] https://datatracker.ietf.org/doc/draft-ietf-openpgp-nist-bp-comp/

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQQwbnhHy1kPJkWsM6fk2On5l6gz3QUCaPnpdQUDAAAAAAAKCRDk2On5l6gz3Qx+
AP9xcoajLwnqEB2ONFkxVDw3HOLExe/7s6+FywBCS0wKRAD/dAoqG1msUE0k7s8ExOZNBa2MqpgU
lvq9dRdz0cva1QE=
=g0IE
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.