[{"author": "Benson Muite", "text": "<p>Happy to help</p>", "time": "2026-07-21T12:01:49.000Z"}, {"author": "Michael P", "text": "<p>Thanks Benson</p>", "time": "2026-07-21T12:02:27.000Z"}, {"author": "Sophie Schmieg", "text": "<p>But that will spell doom for <a href=\"https://www.howmanydayssinceajwtalgnonevuln.com/\">https://www.howmanydayssinceajwtalgnonevuln.com/</a></p>", "time": "2026-07-21T12:09:01.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>@sophie, not necessarily, implementations will still do stupid long after we tell then not to.</p>", "time": "2026-07-21T12:16:11.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>Strictly speaking, if we adopt the draft, whether it is sensible or not is irrelevant because the group fixes it. All that matters is this an interesting question and do we have a realistic chance of solving it.</p>", "time": "2026-07-21T12:20:44.000Z"}, {"author": "Orie Steele", "text": "<p>TIL: Lazer - <a href=\"https://eprint.iacr.org/2024/1846\">https://eprint.iacr.org/2024/1846</a></p>", "time": "2026-07-21T12:21:52.000Z"}, {"author": "Bas Westerbaan", "text": "<p>For short statements, VOLEitH combined with multivariate signatures seem like the most promising path for PQ ZKPs. Something similar to eg. <a href=\"https://eprint.iacr.org/2026/109\">https://eprint.iacr.org/2026/109</a> but that can actually be improved quite a bit</p>", "time": "2026-07-21T12:23:43.000Z"}, {"author": "David Waite", "text": "<p>its all lasers, voles, and mayo trapdoors to me</p>", "time": "2026-07-21T12:25:01.000Z"}, {"author": "Orie Steele", "text": "<p>I like the idea of some agility on zkp attribute commitment</p>", "time": "2026-07-21T12:25:03.000Z"}, {"author": "Bas Westerbaan", "text": "<p><span aria-label=\"heart\" class=\"emoji emoji-2764\" role=\"img\" title=\"heart\">:heart:</span>  fewer options</p>", "time": "2026-07-21T12:26:32.000Z"}, {"author": "Orie Steele", "text": "<p>^ indeed</p>", "time": "2026-07-21T12:26:38.000Z"}, {"author": "Brent Zundel", "text": "<p>Yes please</p>", "time": "2026-07-21T12:26:51.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>I can't see anyone who is so concerned about security that they do ML-KEM accepting the 512...</p>", "time": "2026-07-21T12:37:15.000Z"}, {"author": "Ivaylo Petrov", "text": "<p>To clarify, COSE meeting in on Thursday.</p>", "time": "2026-07-21T12:40:39.000Z"}, {"author": "Bas Westerbaan", "text": "<p>Summarized: if you use a bad RNG you're in trouble.</p>", "time": "2026-07-21T12:42:49.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>@Bas, it is more extreeme though, if you decide to ignore large chunks of the spec and do it your own way, you can be in trouble.</p>", "time": "2026-07-21T12:44:47.000Z"}, {"author": "Sophie Schmieg", "text": "<p>(also to be clear, I'm not against that wording. I think it's silly, but if it makes people happy I value people's happiness over not being silly)</p>", "time": "2026-07-21T12:47:23.000Z"}, {"author": "Bas Westerbaan", "text": "<p>(Not disagreeing with Deb, but if I'd have to choose between RSA+AES-256 or ML-KEM+3DES, I'm choosing the latter.)</p>", "time": "2026-07-21T12:48:21.000Z"}, {"author": "Quynh Dang", "text": "<p>AES was designed between 1995 and 1998 by Belgian cryptographers Joan Daemen and Vincent Rijmen.</p>", "time": "2026-07-21T12:48:40.000Z"}, {"author": "Sophie Schmieg", "text": "<p><span class=\"user-mention silent\" data-user-id=\"549\">Bas Westerbaan</span> <a href=\"#narrow/channel/358-jose/topic/ietf-126/near/225311\">said</a>:</p>\n<blockquote>\n<p>(Not disagreeing with Deb, but if I'd have to choose between RSA+AES-256 or ML-KEM+3DES, I'm choosing the latter.)</p>\n</blockquote>\n<p>highly cursed idea, but I agree</p>", "time": "2026-07-21T12:49:46.000Z"}, {"author": "Bas Westerbaan", "text": "<p>SLH-DSA-MD5 over RSA-4096</p>", "time": "2026-07-21T12:50:54.000Z"}, {"author": "Orie Steele", "text": "<p>^ if you like combos like that, as sad as our current hpke suites are.. that is exactly why we tried to get alignment on suites.</p>", "time": "2026-07-21T12:51:00.000Z"}, {"author": "Sophie Schmieg", "text": "<p><span class=\"user-mention silent\" data-user-id=\"549\">Bas Westerbaan</span> <a href=\"#narrow/channel/358-jose/topic/ietf-126/near/225339\">said</a>:</p>\n<blockquote>\n<p>SLH-DSA-MD5 over RSA-4096</p>\n</blockquote>\n<p>I think SLH-DSA-md4 is also technically secure</p>", "time": "2026-07-21T12:51:33.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>@Sophie, arguably, the meet in the middle attack on DES is less of a threat these days as the AI folk have bought up every stick of DRAM, SSD and hard drive in existence.</p>\n<p>Unless of course, they are the folk making the attack.</p>", "time": "2026-07-21T12:52:22.000Z"}, {"author": "Orie Steele", "text": "<p>@PHB so you are saying that excessive token consumption is keeping us safe from attacks on DES? I'm doing my part.</p>", "time": "2026-07-21T12:53:06.000Z"}, {"author": "Bas Westerbaan", "text": "<p><span class=\"user-mention silent\" data-user-id=\"5474\">Orie Steele</span> <a href=\"#narrow/channel/358-jose/topic/ietf-126/near/225366\">said</a>:</p>\n<blockquote>\n<p>@PHB so you are saying that excessive token consumption is keeping us safe from attacks on DES? I'm doing my part.</p>\n</blockquote>\n<p>You're absolutely right\u2014great catch!</p>", "time": "2026-07-21T12:53:46.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>@Orie, that or the whole AI thing is just a ruse, ChatGPT really runs on a RaPi somewhere while the monster computer they have built with all the hardware sits waiting to unwind the BitCoin Blockchain... Muahhaahhhaaaa</p>", "time": "2026-07-21T12:54:40.000Z"}, {"author": "Bas Westerbaan", "text": "<p><span aria-label=\"plus\" class=\"emoji emoji-2795\" role=\"img\" title=\"plus\">:plus:</span>  If you use it, keep it as-is.</p>", "time": "2026-07-21T12:58:07.000Z"}, {"author": "Sophie Schmieg", "text": "<p>+1</p>", "time": "2026-07-21T12:58:09.000Z"}, {"author": "Jan Klau\u00dfner", "text": "<p>agree with andrei, its meant as single block</p>", "time": "2026-07-21T12:58:49.000Z"}, {"author": "Orie Steele", "text": "<p>I'll just say it here: if we add ASN.1 here, lets make it really really clear, that you should not pull in a full parser / serializer to do it.</p>", "time": "2026-07-21T12:59:10.000Z"}, {"author": "Orie Steele", "text": "<p>and to be clear, I think we should strive to keep ASN1 out of JOSE in the year of 2026</p>", "time": "2026-07-21T13:00:00.000Z"}, {"author": "Bas Westerbaan", "text": "<p><a href=\"/user_uploads/2/69/G432jcp3Gevezq4TvHfivaYu/image.png\">image.png</a></p>\n<div class=\"message_inline_image\"><a href=\"/user_uploads/2/69/G432jcp3Gevezq4TvHfivaYu/image.png\" title=\"image.png\"><img data-original-content-type=\"image/png\" data-original-dimensions=\"320x180\" src=\"/user_uploads/thumbnail/2/69/G432jcp3Gevezq4TvHfivaYu/image.png/840x560.webp\"></a></div>", "time": "2026-07-21T13:00:26.000Z"}, {"author": "Sophie Schmieg", "text": "<p>I think not seeing signatures/keys as opqaue blobs is one of the design mistakes that have been plaguing JWK/JWT</p>", "time": "2026-07-21T13:01:03.000Z"}, {"author": "Sophie Schmieg", "text": "<p>don't think of it as ASN.1, think of it as the LAMPS thing that has no known structure</p>", "time": "2026-07-21T13:01:31.000Z"}, {"author": "Jan Klau\u00dfner", "text": "<p>+1</p>", "time": "2026-07-21T13:02:09.000Z"}, {"author": "Orie Steele", "text": "<p>+1 sophie</p>", "time": "2026-07-21T13:03:54.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>+1 Sophie</p>", "time": "2026-07-21T13:04:54.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>For private keys, 128/192/256 bit key and deterministic generation scheme (+ hints if needed)</p>", "time": "2026-07-21T13:05:40.000Z"}, {"author": "Jan Klau\u00dfner", "text": "<p>The ASN.1 is also ONLY for the EC part, ML-DSA is kept as byte string as defined by NIST and not additionally wrapped</p>", "time": "2026-07-21T13:05:43.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>If you are doing it yourself, it is because you are writing a crypto library in which case you probably have to support ASN.1 anyway so TLS etc. can use it</p>", "time": "2026-07-21T13:07:40.000Z"}, {"author": "Hannes Tschofenig", "text": "<p>Since Claude will write the code, the decision does not really matter much...</p>", "time": "2026-07-21T13:10:00.000Z"}, {"author": "Phillip Hallam-Baker", "text": "<p>@Hannes, unless all the Claude tokens are being used to break the blockchain...</p>", "time": "2026-07-21T13:10:48.000Z"}, {"author": "Orie Steele", "text": "<p>+1 Hannes... lets help CFRG finish BBS, what can we do to help.</p>", "time": "2026-07-21T13:20:53.000Z"}, {"author": "Karen O'Donoghue", "text": "<p>+1 Orie</p>", "time": "2026-07-21T13:22:26.000Z"}, {"author": "Emil Lundberg", "text": "<p>Re: JWP claims mapping - I think Christian's approach in BBS-MOD is quite elegant, and we should consider adopting that for JWP</p>", "time": "2026-07-21T13:24:06.000Z"}, {"author": "Emil Lundberg", "text": "<p>with the caveat that in practice there'll probably need to be quite strict control on what headers issuers are allowed to issue, to prevent de-anonymization through small variations in the header encoding</p>", "time": "2026-07-21T13:25:16.000Z"}, {"author": "Brent Zundel", "text": "<p>Looking at the authors of BBS, are any of them still active?</p>", "time": "2026-07-21T13:25:47.000Z"}, {"author": "Orie Steele", "text": "<p>perhaps we can get some additional authors added to BBS in CFRG to pull / push it over the line.</p>", "time": "2026-07-21T13:25:52.000Z"}, {"author": "Brent Zundel", "text": "<p>I'm willing to work on it</p>", "time": "2026-07-21T13:26:44.000Z"}, {"author": "Emil Lundberg", "text": "<p>I've been contributing to Blind BBS recently, but not yet BBS core</p>", "time": "2026-07-21T13:27:24.000Z"}, {"author": "Tadahiko Ito", "text": "<p>feature 1 (archiving document) is achieved by  counter signature.</p>", "time": "2026-07-21T13:29:05.000Z"}, {"author": "Tadahiko Ito", "text": "<p>JAdES is European, very rich mechanism, and this one is relatively \"lightweight\"</p>", "time": "2026-07-21T13:29:38.000Z"}, {"author": "Orie Steele", "text": "<p>There is also: <a href=\"https://datatracker.ietf.org/doc/rfc9921/\">https://datatracker.ietf.org/doc/rfc9921/</a></p>", "time": "2026-07-21T13:34:01.000Z"}]