On Wed, Jan 07, 2026 at 07:32:42PM +0000, Michael Jones wrote: > As John Bradley said during the discussion of the draft in Montreal, > if we don't do this, somebody else will. Better that we do it.
Regarding somebody else doing it... draft-ietf-lamps-pq-composite-sigs uses ASN.1 for ECDSA. This introduces a good chunk of complexity into signature verification code[1], which is among the worst places to have excess complexity in. [1] I have written (just to check complexity) code to parse ML-DSA/ECDSA composite signatures with ASN.1 and IEEE encodings[2]. There is very big difference in complexity between the two. [2] IEEE encoding is used by COSE and JOSE for ECDSA. -Ilari _______________________________________________ jose mailing list -- [email protected] To unsubscribe send an email to [email protected]
