freenode

← digests

IETF PQ crypto advances and protocol governance debates

Internet & Protocols2026-07-31

IETF working groups pushed post-quantum cryptography proposals for SSH and TLS while other lists examined authentication status, hardware key support, AI preference categories, and DNS operational issues. Activity ranged from heated adoption calls to quieter technical refinements.

SSH WG Call for Adoption of ML-DSA Signature Drafts

The IETF SSH working group opened a call for adoption of hybrid and pure ML-DSA signature drafts, closing August 17th. Discussion across dozens of messages featured clashes between Daniel J. Bernstein and the chairs over safety arguments, including references to new AI cryptanalysis. The outcome will influence how post-quantum authentication is standardized in SSH.

Keccak-Based TLS 1.3 Key Schedule Draft

A new IETF draft proposes a Keccak-based key schedule for TLS 1.3. Members of the Keccak team and volunteers focused on formal analysis joined the thread to examine optimizations. The work matters for implementers seeking alternative constructions in the TLS handshake.

Last Call on ML-KEM for TLS 1.3

The IETF announced last call on the draft that registers ML-KEM post-quantum NamedGroups for TLS 1.3, targeting Informational RFC status. The short exchange confirms the document is ready for broader review. Adoption would give TLS deployments a standardized post-quantum key agreement option.

DMARC Discussion on Historic Status for ARC

The DMARC working group evaluated consensus on marking ARC (RFC 8617) as Historic and publishing an accompanying experiment report. Participants weighed the protocol's limited deployment against the value of documenting lessons learned. The decision affects how future authenticated email forwarding is specified.

OpenPGP Card Encoding for Modern Key Packets

OpenPGP list participants examined an encoding scheme that maps 20-byte card fingerprint fields onto v6 OpenPGP keys. The goal is to let existing hardware security devices support the newer key packet format. Hardware token users and library authors need a clean migration path without breaking current cards.

AI Preference Categories for Inference and User Input

The AIPREF working group discussed a pull request that adds "AI System Inference" and "AI User Input" categories. Debate centered on precise definitions and the intended scope of each label. Clear categories help content owners signal how their material may be used by AI systems.

SPICE Affirms GLUE URI Registration

The SPICE working group reaffirmed its request to register a GLUE URI following earlier IETF 126 discussion. The affirmation proceeded despite objections from Roy Fielding that IANA would be duplicating DNS authority. The registration clarifies identity binding for the group's credential formats.

NANOG Thread on Domain Seizure and Mitigation Tradeoffs

A NANOG thread examined a Texas court seizure of a .com domain and the operational tradeoffs of RTBH versus Flowspec responses. Participants treated the incident as an instance of political overreach with concrete routing consequences. Network operators must weigh legal exposure against traffic-filtering techniques.