Post #1137834
2026-04-13 19:36 UTC
Replies (2)
-
@huitema@social.secret-wg.org 2026-04-13 19:45
@djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange The IETF has a strong bent towards "publishing rather than censoring", unless the technical flaws are obvious. That bent drives strongly towards "publishing with some proper warning in the text", while not publishing at all would be pretty extraordinary, especially in presence of a constituency that really want to sell products to the US government. So at that stage of the debate, the issue is really about how strong the warning should be.
-
@huitema@social.secret-wg.org 2026-04-13 19:41
@djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange So the question for the PQ-only algorithms is not whether the IETF can prevent deployment (it cannot), but whether publishing these algorithms as RFCs is necessary or harmful. There is consensus that it is not necessary, since the IANA registrations do not require it. What we see is mostly a debate on whether it is harmful, because it would help promoting an unproven algorithm that might be compromised. This is where opinions vary.