Elektrine lite

← Feed

@djb@mastodon.cr.yp.to

Post #1120211

2026-04-10 21:10 UTC

@argv_minus_one@mastodon.sdf.org I have an introductory chart https://blog.cr.yp.to/20260221-structure.html showing the arguments and counterarguments. Most common argument from proponents: NSA is asking for non-hybrids, ergo support non-hybrids. This argument works for (1) companies chasing NSA money, (2) companies that take any excuse for extra options as a barrier to entry for competitors, and (3) people who think that "NSA Cybersecurity" isn't a conduit for https://www.eff.org/files/2014/04/09/20130905-guard-sigint_enabling.pdf but rather an independent pro-security agency.

Replies (3)

  • @rsalz@ioc.exchange 2026-04-10 21:41

    @darkuncle@infosec.exchange Sorry to see you promoting this. He's done great work, but this whole thread is crazy conspiracy thinking.

    Open ##1120210

  • @djb Welp, I think it's safe to assume that ML-KEM is already broken and so is the IETF TLS committee. Lovely.

    Open ##1249798

  • @tasket@infosec.exchange 2026-04-13 17:38

    @djb I think the quote you included here In June 2025, NSA's Mike Jenkins posted the following: "As the CNSA 2.0 profiles should make clear, we are looking for products that support /standalone/ ML-DSA-87 and /standalone/ ML-KEM-1024. If there is one vendor that produces one product that complies, then that is the product that goes on the compliance list and is approved for use. Our interactions with vendors suggests that this won't be a problem in most cases." Evidently there are many companies happy to jump when NSA says jump. ...shows that corporate interests within the IETF are a matter of concern, even if overt pressure isn't being used. IETF should be taking precautions to address such concerns. Thank you raising this issue, Daniel.

    Open ##1249834