On Wed, Jan 10, 2024 at 12:14 PM Bas Westerbaan
<bas=40cloudflare....@dmarc.ietf.org> wrote:
>
> Dear tls and cfrg working groups,
>
> With ML-KEM (née Kyber) expected to be finalized this year, it’s time to 
> revisit the question of which PQ/T hybrid KEMs to standardize, and which to 
> recommend.

My preference would be that we use an KEM hybrid that works not just
for TLS but for HPKE etc with all the parameters set. I think its fine
if adapted for ML-KEM as is. Remembering which works here and which
doesn't there is work that we don't need to do and if gotten wrong
could cause problems.

Sincerely,
Watson


-- 
Astra mortemque praestare gradatim

_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to