Post B5GHP7BIFbZ0fNdjiC by djb@cr.yp.to
(DIR) More posts by djb@cr.yp.to
(DIR) Post #B5GH08Xk388DeREI9A by djb@cr.yp.to
1 likes, 0 repeats
The IETF TLS chairs have now issued a "last call" for objections to non-hybrid signatures in TLS. Do they admit that their previous "last call" re non-hybrid KEMs ended up with a _majority_ in opposition, and that many opposition statements obviously also apply to signatures? No.
(DIR) Post #B5GHP7BIFbZ0fNdjiC by djb@cr.yp.to
0 likes, 0 repeats
@jzb @rsalz @darkuncle Side note re "crypto expert": The issue here is basic security risk management. For example, Google and Cloudflare tried ECC+SIKE (CECPQ2b: https://web.archive.org/web/20260411125124/https://blog.cloudflare.com/the-tls-post-quantum-experiment/) for tens of millions of user connections, and then SIKE was publicly broken years later. The only reason this didn't immediately expose all those user connections to attackers is that the connections were still encrypted with ECC.
(DIR) Post #B5GHP7hYJfMsHQjUzg by darkuncle@infosec.exchange
1 likes, 0 repeats
@djb @jzb @rsalz belt and suspenders