> Suppose the payment card industry standards (PCI-DSS) says they want
> all terminals to move to PQ, and in particular MLKEM. Would that > bother you? Well, you know I'm easily bothered:-) If "move to PQ" meant no hybrid stuff for TLS, I'd really wonder why. That’s easy to answer: “many of our members have very hardware-constrained PoS devices.” Is that okay? The real question I was asking, I didn’t make clear: if commercial groups came to the same end result as, say, the US Dept of Defense, would you be okay with that?
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-le...@ietf.org