TLS hybrids standardized as pure ML-KEM last call heats up
The IETF published a Proposed Standard for post-quantum hybrid key agreement in TLS 1.3 while a last call on pure ML-KEM drew sharp disagreement over security risks. Adoption calls for AI agent authentication and OAuth RAR metadata advanced with broad support, alongside heated debates on attestation binding and CBOR validation rules.
RFC 10024 standardizes PQ/T hybrid key agreement for TLS 1.3
The IETF published RFC 10024 defining ML-KEM hybrid key agreement mechanisms for TLS 1.3 as a Proposed Standard. The document covers Post-Quantum Traditional (PQ/T) hybrid approaches that combine classical and post-quantum cryptography. TLS implementers gain a stable reference for hybrid key exchange that mitigates risks from future quantum attacks while retaining traditional security properties.
Last call dispute over pure ML-KEM for TLS 1.3
A last call on draft-ietf-tls-mlkem-09 proposes publishing non-hybrid ML-KEM post-quantum key agreement for TLS 1.3 as an Informational RFC. Opponents argued that unaddressed security risks remain, while supporters cited working group consensus. The outcome will shape whether pure post-quantum key exchange proceeds without hybrid safeguards.
WIMSE call for adoption of AI agent authentication
The WIMSE working group opened a call for adoption of draft-klrc-aiagent-auth covering AI agent authentication and authorization. Twelve of fourteen replies offered mostly support, though some participants dissented on scope and taxonomy. The draft could establish baseline mechanisms for authenticating autonomous agents in internet protocols.
SEAT debate on early attestation transcript binding
The SEAT working group debated whether draft-fossati-seat-early-attestation-06 transcript binding prevents relay attacks linked to intra-handshake.fail and CVE-2026-33697. Thirty-one messages from nine participants examined the binding strength against intra-handshake threats. Resolution matters for the security of early attestation flows against known relay vectors.
OAuth call for RAR metadata and error remediation
The OAuth working group issued a call for adoption of a draft on OAuth 2.0 RAR Metadata and Error Remediation. Fourteen participants gave unanimous early support. Adoption would add structured metadata and clearer error handling to rich authorization requests.
AI preference vocabulary categories under discussion
The aipref working group considered proposed AI System Inference and AI User Input categories for preference vocabulary. Participants disagreed on scope, process ordering, and whether the categories provide full opt-out coverage. The additions would expand how systems signal AI-related processing preferences.
CBOR validators diverge on bignum and CDDL matching
A CBOR thread examined whether CDDL #0 matches bignum tags under the unification rules of RFC 8949, which affects RFC 8610 validation. Disagreement among nine participants exposed divergence among existing validators. Consistent interpretation is required for reliable CDDL-based CBOR validation.
CBOR EDN literals draft faces feature cuts
The CBOR working group discussed removing or fixing controversial features from draft-ietf-cbor-edn-literals, specifically the CRI app-extension, the unknown-app CPA999 tag, and block comments. Five participants weighed the changes as a path to consensus. Trimming the draft could unblock progress on extended diagnostic notation.