On Wed, Jan 07, 2026 at 07:32:42PM +0000, Michael Jones wrote:
> As John Bradley said during the discussion of the draft in Montreal,
> if we don't do this, somebody else will.  Better that we do it.

Regarding somebody else doing it... draft-ietf-lamps-pq-composite-sigs
uses ASN.1 for ECDSA. This introduces a good chunk of complexity into
signature verification code[1], which is among the worst places to have 
excess complexity in.


[1] I have written (just to check complexity) code to parse ML-DSA/ECDSA
composite signatures with ASN.1 and IEEE encodings[2]. There is very big
difference in complexity between the two.

[2] IEEE encoding is used by COSE and JOSE for ECDSA.




-Ilari

_______________________________________________
jose mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to