Post #1139748
2026-04-13 19:41 UTC
@djb@mastodon.cr.yp.to @paulehoffman@infosec.exchange @rsalz@ioc.exchange So the question for the PQ-only algorithms is not whether the IETF can prevent deployment (it cannot), but whether publishing these algorithms as RFCs is necessary or harmful. There is consensus that it is not necessary, since the IANA registrations do not require it. What we see is mostly a debate on whether it is harmful, because it would help promoting an unproven algorithm that might be compromised. This is where opinions vary.
Replies (1)
-
@djb@mastodon.cr.yp.to 2026-04-13 20:17
@huitema@social.secret-wg.org @paulehoffman@infosec.exchange @rsalz@ioc.exchange I've been tracking the arguments and counterarguments (see https://blog.cr.yp.to/20260221-structure.html for a chart) and I don't see where you're getting this "promoting" idea from. Both sides of the debate want to roll out PQ to try to stop quantum attacks. The difference is that one side says you're allowed to replace ECC with _just_ PQ, whereas the other side is requiring ECC+PQ (at negligible extra cost) to reduce the damage caused by more failures of PQ security.