[saag] Re: post quantum guidance draft

Stephen Farrell <[email protected]> Fri, 12 Dec 2025 11:58:58 +0000
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Hiya,

Answering a few posts in one...

On 11/12/2025 21:17, Salz, Rich wrote:
 > Thanks for the work and making this available. The current survey of
 > IETF work seems even-handed. I’m not sure it gives much
 > justification for your draft, tho.

I'm not claiming it does, but I do claim it's evidence that the
size and semi-(dis)organised complexity of the PQ zoo means we
owe it to people using our stuff to try provide guidance.

 > Do you think all the WGs will end up using the same signature
 > algorithms?

No, one suggestion has been to use different sig algs even
on one cert path, e.g. something hash-based for the root,
maybe fn-dsa in the middle and ml-dsa for the end-entity.
(Add in the parameters sets there too.) And IIUC there's no
current story about how to operate such a PKI (acme etc.).

And the above ignores the hybrid sig thing entirely. (As it
ought:-)



On 12/12/2025 07:38, John Mattsson wrote:
 > Being sceptic of the quantum computers is perfectly reasonable, but
 > it raises the question: what assumptions lead to the recommendation
 > in [3]?

I'm skeptical about current proposed mitigations for a putative-CRQC
but not about the risk of there being a CRQC. (I'd maybe consider
the risk smaller than others' would, but as a non-zero probability I
think we do need to address the risk.)

 > A common position is that there is a meaningful chance of a CRQC
 > being built within the next 15 years. If that assumption is true,
 > then we urgently need to migrate signatures in long-lived devices.

That's a point on which I disagree. I know you and others express
that need, but IMO jumping now will lead to worse longer term
outcomes as the PQ signature technology is not ready for that.

 > Recommending inaction in that scenario is like having your house on
 > fire, arguing about whether to use a powder or foam extinguisher,
 > and ultimately deciding to recommend doing nothing.

Yeah - analogies don't win the argument:-) Also: "Something must be
done. This is a thing. This thing must be done." is as good/bad an
argument.

 > Also note that the likelihood of someone building a CRQC is not
 > independent of our migration choices. Migrating everything now
 > significantly reduces the incentive for any government to invest in
 > building a CRQC in the first place.

Migrating everything doesn't seem to be required for that argument.
One might consider that migrating KEMs could suffice.

Also, migrating before the technology is ready (as in sigs) could
incentivise bad actors to keep us worrying about CRQC's so that we
introduce more non-cryptographic vulns while prematurely migrating.



On 12/12/2025 09:46, John Mattsson wrote:
 > If the IETF issues guidance, I strongly believe it should explicitly
 > address long-lived devices.

What'd you suggest that say?



On 12/12/2025 09:54, Bas Westerbaan wrote:
 > Let's not forget about the time it takes to migrate, even for
 > updateable software and short-lived devices.

Sure, doing things takes time. We're ready to do things wrt KEMs.
Doing things too soon may take more time if/as we have to re-do
things having mucked up first time.

Cheers,
S.

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQQwbnhHy1kPJkWsM6fk2On5l6gz3QUCaTwDggUDAAAAAAAKCRDk2On5l6gz3bOw
AQD61+u1eMrw8NxpaV//qMp0+xbkkRCKR8qpAU8rqa1vbQD+JL6jybxFo+MrHmP9inOSNONpcRG2
FfDBDz0GCvI8SQY=
=TJtM
-----END PGP SIGNATURE-----