Elektrine lite

← Feed

@djb@mastodon.cr.yp.to

Post #1139745

2026-04-14 01:24 UTC

@huitema@social.secret-wg.org @paulehoffman@infosec.exchange @rsalz@ioc.exchange It's important to distinguish the non-controversial part (rolling out a PQ layer) from the controversial part (_removing_ the existing ECC layer rather than _supplementing_ the existing ECC layer). Saying that the objection is to "promoting an unproven algorithm" misunderstands what's actually at issue. Same for lumping both parts together into a combined "approach" and saying the objection is to that.

Replies (1)

  • @djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange I don't understand what you mean by "removing". The hybrid key exchanges are defined in https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/, which went through IETF last call and is in the final stage of approval by the IESG. I don't know that anybody is proposing to remove that.

    Open ##1139744