Might I point out how silly this argument is?

Ken is complaining that NSA wants to use a group with "only" 192 bits of 
security strength, while what we generally use is x25519, which has a security 
strength of 126 bits (by the same metric).

Could Dan Bernstein (designer of x25519) be accused of deliberately weakening 
security?  Could the TLS working group also be accused, by not only permitting 
that, but other additional "weak" groups as well (P256, all the finite field 
groups) and AES-128?

If you want to make the case to the working group that it should deprecate all 
"below 256 bit" crypto, such as X25519MLKEM768 and SecP256r1MLKEM768, and 
instead rely only on things such as mlkem1024, please make the case.  I 
personally don't have any concerns about the prequantum security of either 
x25519 or P384, but if the working group decides otherwise, so be it.

In any case, the CNSA requirements apply only to US National Security Systems; 
anyone else can do anything they want.  I believe that it is reasonable for an 
organization to make requirements on what is used in their internal network, as 
much as you don't approve of those decisions.

________________________________
From: Ken Kubota <[email protected]>
Sent: Saturday, July 11, 2026 7:00 AM
To: Deb Cooley <[email protected]>
Cc: [email protected] 
<[email protected]>; [email protected] <[email protected]>
Subject: [TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)

"I'm not sure what your point is here"
Although strong cryptography (256 bits of security) could generally have been 
available for every end user for the past two decades on standard consumer 
devices, the U.S. government is intentionally deploying, through the NSA, 
degraded (weakened) encryption.
RFC 9151 (2022), which provides only 192 bits of security (curve P-384), is one 
example.
This is contrary to RFC 8890 ("The Internet is for End Users"), which I 
interpret as meaning that U.S. government interests must not take precedence 
over those of end users (i.e., human beings, mankind). Strong cryptography (256 
bits of security) should be available to everyone.

In my opinion, the warning email [1] constitutes a violation of RFC 3934 
Section 2, and therefore I asked questions 1, 2, 3, and 4 in the section 
addressed to you [2], which you decided not to answer except for the first part 
of question 1, even though they could be answered with a simple "yes" or "no" 
(or a short sentence).
This creates the impression that the rules are applied very restrictively to 
some people [3], while not being applied at all to others.

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to