TLS ML-KEM consensus and CFRG hybrid debates
IETF TLS chairs declared rough consensus on a pure ML-KEM draft while CFRG reviewed hybrid signature and KEM proposals under last call. Parallel threads addressed conflict complaints, OpenPGP discovery, and NomCom composition.
TLS chairs declare rough consensus on pure ML-KEM
IETF TLS chairs declared rough consensus on the pure ML-KEM draft after a consensus call that weighted expert versus new participants amid hybridization objections. The decision follows the working group last call on draft-ietf-tls-mlkem-08. This shapes the path for post-quantum key exchange in TLS deployments.
CFRG debates Silithium hybrid signature draft
A new draft proposes Silithium as a compact, efficient, and non-separable hybrid signature. The CFRG thread examines its security properties, hedging, and code size relative to alternatives such as Mothma. The discussion informs choices among hybrid post-quantum signature constructions.
Hybrid KEM drafts face RG last call comments
CFRG opened research group last call on draft-irtf-cfrg-hybrid-kems-12 and draft-irtf-cfrg-concrete-hybrid-kems-04. Technical comments include objections from Bernstein on combiners and overall complexity. Results will guide hybrid post-quantum and traditional key encapsulation designs.
Security AD answers CoI complaints on TLS list
Security AD Deb Cooley responded to conflict of interest complaints tied to NSA history. The thread interleaves personal attacks with debate over ML-KEM pre-hashing. The exchange underscores governance frictions around cryptographic standardization.
Provider-assisted OpenPGP key discovery proposed
A new proposal outlines provider-assisted OpenPGP key discovery. Replies connect it to ongoing Key Transparency and HKP work in the working group. Adoption could streamline key lookup for OpenPGP users.
Gendispatch weighs NomCom gender quota draft
Gendispatch discussed extending gender quotas to Nominating Committee selection. Comments address privacy versus public verifiability tradeoffs in the composition and comportment draft. The outcome affects IETF leadership selection mechanics.
Secdispatch eyes FrodoKEM RFC to sidestep ISO fees
Participants discussed publishing a FrodoKEM specification as an RFC. The goal is to avoid paid ISO normative references in post-quantum cryptography drafts. The step would keep algorithm documents freely available.
Signed ECH update drops PKIX for retry auth
An updated draft removes PKIX from signed ECH retry authentication. Ben Schwartz and EKR debate replay protection, compromise, and recovery trade-offs. The change refines encrypted client hello recovery options in TLS.