Post #1120211
2026-04-10 21:10 UTC
Replies (3)
-
@rsalz@ioc.exchange 2026-04-10 21:41
@darkuncle@infosec.exchange Sorry to see you promoting this. He's done great work, but this whole thread is crazy conspiracy thinking.
-
@argv_minus_one@mastodon.sdf.org 2026-04-10 21:27
@djb Welp, I think it's safe to assume that ML-KEM is already broken and so is the IETF TLS committee. Lovely.
-
@tasket@infosec.exchange 2026-04-13 17:38
@djb I think the quote you included here In June 2025, NSA's Mike Jenkins posted the following: "As the CNSA 2.0 profiles should make clear, we are looking for products that support /standalone/ ML-DSA-87 and /standalone/ ML-KEM-1024. If there is one vendor that produces one product that complies, then that is the product that goes on the compliance list and is approved for use. Our interactions with vendors suggests that this won't be a problem in most cases." Evidently there are many companies happy to jump when NSA says jump. ...shows that corporate interests within the IETF are a matter of concern, even if overt pressure isn't being used. IETF should be taking precautions to address such concerns. Thank you raising this issue, Daniel.