[saag] Re: post quantum guidance draft
Stephen Farrell <[email protected]> Fri, 12 Dec 2025 11:58:58 +0000
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Hiya, Answering a few posts in one... On 11/12/2025 21:17, Salz, Rich wrote: > Thanks for the work and making this available. The current survey of > IETF work seems even-handed. I’m not sure it gives much > justification for your draft, tho. I'm not claiming it does, but I do claim it's evidence that the size and semi-(dis)organised complexity of the PQ zoo means we owe it to people using our stuff to try provide guidance. > Do you think all the WGs will end up using the same signature > algorithms? No, one suggestion has been to use different sig algs even on one cert path, e.g. something hash-based for the root, maybe fn-dsa in the middle and ml-dsa for the end-entity. (Add in the parameters sets there too.) And IIUC there's no current story about how to operate such a PKI (acme etc.). And the above ignores the hybrid sig thing entirely. (As it ought:-) On 12/12/2025 07:38, John Mattsson wrote: > Being sceptic of the quantum computers is perfectly reasonable, but > it raises the question: what assumptions lead to the recommendation > in [3]? I'm skeptical about current proposed mitigations for a putative-CRQC but not about the risk of there being a CRQC. (I'd maybe consider the risk smaller than others' would, but as a non-zero probability I think we do need to address the risk.) > A common position is that there is a meaningful chance of a CRQC > being built within the next 15 years. If that assumption is true, > then we urgently need to migrate signatures in long-lived devices. That's a point on which I disagree. I know you and others express that need, but IMO jumping now will lead to worse longer term outcomes as the PQ signature technology is not ready for that. > Recommending inaction in that scenario is like having your house on > fire, arguing about whether to use a powder or foam extinguisher, > and ultimately deciding to recommend doing nothing. Yeah - analogies don't win the argument:-) Also: "Something must be done. This is a thing. This thing must be done." is as good/bad an argument. > Also note that the likelihood of someone building a CRQC is not > independent of our migration choices. Migrating everything now > significantly reduces the incentive for any government to invest in > building a CRQC in the first place. Migrating everything doesn't seem to be required for that argument. One might consider that migrating KEMs could suffice. Also, migrating before the technology is ready (as in sigs) could incentivise bad actors to keep us worrying about CRQC's so that we introduce more non-cryptographic vulns while prematurely migrating. On 12/12/2025 09:46, John Mattsson wrote: > If the IETF issues guidance, I strongly believe it should explicitly > address long-lived devices. What'd you suggest that say? On 12/12/2025 09:54, Bas Westerbaan wrote: > Let's not forget about the time it takes to migrate, even for > updateable software and short-lived devices. Sure, doing things takes time. We're ready to do things wrt KEMs. Doing things too soon may take more time if/as we have to re-do things having mucked up first time. Cheers, S. _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
OpenPGP_signature.asc
(application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE----- wnsEABYIACMWIQQwbnhHy1kPJkWsM6fk2On5l6gz3QUCaTwDggUDAAAAAAAKCRDk2On5l6gz3bOw AQD61+u1eMrw8NxpaV//qMp0+xbkkRCKR8qpAU8rqa1vbQD+JL6jybxFo+MrHmP9inOSNONpcRG2 FfDBDz0GCvI8SQY= =TJtM -----END PGP SIGNATURE-----