freenode
Internet & Protocols

IETF SSH group weighs pure vs hybrid post-quantum signatures

A three-week adoption call pits NIST and FIPS-driven demand for standalone ML-DSA against warnings that new PQ code will ship with exploitable bugs.

The IETF SSH maintenance working group has opened a three-week call for adoption of post-quantum signature drafts, aiming to pick one starting point for hybrid ECC-plus-ML-DSA schemes and one for pure ML-DSA. The call, run by chairs Stephen Farrell and Job Snijders, closes 17 August.

The choice is already contested. Cryptographer D. J. Bernstein argues that pure ML-DSA should be dropped. Drawing on a recent paper and talk that model historical CVE rates in cryptographic libraries, he estimates a steady stream of severe ML-DSA implementation flaws will leave large numbers of keys breakable each year. An ECC hybrid layer, he says, would often contain the damage at negligible cost. Several participants, including Gert Doering and Ken Kubota, found the risk argument compelling and prefer hybrids that keep a classical algorithm in the path.

Others insist pure ML-DSA must be specified now. RJ Atkinson cited long-standing practice of following US NIST guidance and FIPS-140 modules; insurers in finance and other sectors commonly require both. Scott Fluhrer, author of one pure-ML-DSA draft, noted that after a cryptographically relevant quantum computer arrives the classical component adds little security, so both hybrid and pure camps should be accommodated. Panos Kampanakis likewise backed adopting a merged hybrid draft plus Fluhrer’s pure draft, observing that some deployments will reject dual identities or double verify costs.

Simon Josefsson went further, urging the group to adopt only strong hybrids (for example Ed25519 combined with ML-DSA or SLH-DSA) and to defer pure schemes until PQ implementations mature. Chairs have asked respondents to name preferred starting drafts without yet debating algorithm combinations, parameter sizes or SLH-DSA; those topics are reserved for a later interim.

The outcome will shape what OpenSSH and other implementations can interoperate on as post-quantum migration accelerates.