Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What a weird comment.

> where you think NSA "proposed" MLKEM or had some hand in its design

Never said this and don't think it.

Kyber came from an academic team through an open NIST competition, no one is disputing that. The fight is over a spec for deploying ML-KEM without the ECC layer, and the fact that NSA and GCHQ are argumenting that that weakening is a good thing, and about corrupt standardization process.

 help



No it isn't! Everyone is fine with hybrids, hybrids are the default, and hybrids have a standards-track, recommended=y RFC, unlike pure. If you think this is about hybrids, Bernstein has bamboozled you.

Again you responded to a position I havent taken. My argument was about who holds procedural power in standards bodies, given that some of the significant participants (NSA & GCHQ) have funded programs with hundreds of millions of $ per year to make deployed cryptography exploitable. And DES and Dual EC and others are what that looks like when it succeeds.

It sounds like what's actually happening here is you're fleeing to an abstraction after acknolwedging that (a) NSA couldn't have had a hand in designing MLKEM and (b) that nobody at IETF is advocating against hybrids --- indeed, it's literally the opposite. But now it's about Ethics In Games Journalism.

The problem with your claim that there's a corrupt institutional process --- apart from knowing who the people are behind this "institution" and finding it risible that any of them are taking cues from NIST, let alone NSA --- is that the institutional is already delivering the outcome you say you favor: default, Recommended=Y, standards track hybrid constructions, the ones used by all mainstream software with PQC.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: