Post #1120203
2026-04-13 05:57 UTC
@djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange I don't know for 2012, but from 2013 on a large number of IETF participants were absolutely convinced of being under attack. It was fairly obvious that some IETF participants were either willing enablers of these attacks, or "useful idiots". But we don't know which ones, and we quickly realized that launching a witch-hunt would be very destructive, and that the safest path was to keep discussions strictly technical.
Replies (2)
-
@djb@mastodon.cr.yp.to 2026-04-13 07:20
@huitema@social.secret-wg.org @paulehoffman@infosec.exchange @rsalz@ioc.exchange Using ECC+PQ instead of non-hybrid PQ is a straightforward, low-cost, broadly recommended, broadly deployed technical step to limit the damage from PQ security failures (such as the SIKE break and KyberSlash). The problem at hand is non-technical, namely NSA pressuring various companies such as Cisco to support non-hybrid PQ. See https://blog.cr.yp.to/20251004-weakened.html#tls for quotes from employees of NSA and Cisco admitting this.
-
@eliotlear@mastodon.social 2026-04-13 06:28
@huitema I would argue that what we had at the time was a frenzied mob, particularly in Vancouver.