Elektrine lite

← Feed

@huitema@social.secret-wg.org

Post #1249777

2026-04-15 07:05 UTC

@djb @pedromj @paulehoffman @rsalz In fact, there are many WG members arguing that we do not need an ML-KEM RFC since the NIST specification can just be deployed today. The counter to that argument is that publication as an RFC provides a stable reference, which helps interoperability, plus provides the IETF with a modicum of control. The counter to that counter argument is that RFC publication is mostly a marketing attempt, to make the algorithm easier to "sell".

Replies (2)

  • @djb @pedromj @paulehoffman @rsalz Easier to sell is pretty much the same as "Endorsement by the IETF". At that point, the technical arguments boil down to the risk that ML-KEM is found broken. Dan, you argue that that risk is very high because the promotion efforts are orchestrated by the government. But if people were to discard your argument, we are left with a generic discussion of risk. That discussion could result in having a recommendation=Y for hybrids versus no for naked. Maybe.

    Open ##1249778

  • @djb@mastodon.cr.yp.to 2026-04-15 07:39

    @huitema @pedromj @paulehoffman @rsalz The core issue is endorsement. It isn't about having a stable reference; having a stable reference doesn't need an RFC. It isn't about interoperability; interoperability doesn't need an RFC. The "control" argument is circular; https://archive.cr.yp.to/2026-04-10/05:38:16/1w0wAgKE9fiKZKunAg8qCyVyWYZ4j-aHgW-0aFDzgcw/https/mailarchive.ietf.org/arch/msg/tls/LqG-gHxgRvVPebE3m28D8VT7dN4/ spells this out in baby steps.

    Open ##1249780