The “Why” is explained by Bas Westerbaan and Christopher Patton from Cloudflare.
From the blogpost:
“[…] ML-DSA, the best all-around post-quantum signature scheme standardized today, has its downsides: it’s much larger on the wire, and many tricks we were able to perform with RSA and ECC simply cannot be done with ML-DSA. There are better post-quantum signature schemes on the horizon: last month, NIST announced that it is advancing nine post-quantum signature schemes to the third round of the “signatures on-ramp”. And a draft standard for FN-DSA (née Falcon), which was picked from the previous competition, is expected imminently. […]
But first we have to deal with the elephant in the room: These new signature algorithms will not be ready in time for the PQ transition — not even close, as we will see later on. The problem is arriving too soon for us to wait. ML-DSA is available today, and it will have to do for the first migration. As Eric Rescorla wrote in 2024: ‘You go to war with the algorithms you have, not the ones you wish you had.’ “
- More information, origin of text: https://blog.cloudflare.com/ml-dsa-will-have-to-do
- Foto von Markus Spiske auf Unsplash