[TLS] Re: [Last-Call] Re: Re: Last Call: <draft- ietf-tls-mlkem-09.txt> (ML-KEM Post-Quantum Key Agreement f or TLS 1.3) to Informational RFC
"Salz, Rich" <[email protected]>
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <MN2PR17MB4031C334D78098B57C60A1F9CDDC2@MN2PR17MB4031.namprd17.prod.outlook.com> |
On 8/11/26, 5:34 PM, "Erwin Hoffmann" <[email protected]> wrote: * 3. However, I feel very uncomfortable about the way the discussion of * that draft is going on. Given my understanding (and supporting TLS 1.3 * since its first beginning), the main purpose of a communication and * security-aware protocol is risk-minimization or at least risk- * migitation for the user. That is the baseline and should be obeyed at * each and every step (enforced by the Chair). It is more subtle then that. If it were purely about risk minimization, then we would just pick incredibly large key sizes. Security is all about trade-offs, and the cryptography used is just one part, the entire system being developed and deployed must be considered, and many experienced members of this working group are fine with ML-KEM for some deployments, as documented in the to-be-RFC. * 4. The way the random number is used in ML-KEM, does IMHO not conform * … Correct me, if I’m wrong. David Benjamin has already explained why this is wrong and therefore your bottom-line also seems wrong: * 5. Thus, at the bottom-line, the Master Secret depends solely of the _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]