On Wed, 16 Apr 2025, Blumenthal, Uri - 0553 - MITLL wrote:
Sure. On the same note – how do we know that there will be no new research findings about ECC? (Besides the fact that once CRQC is built, it becomes useless.)
Not uselesss. It would still be a good anti-ddos / cookies technique until each phone is a CRQC. Especially if you do an ECC exchange before a PQ exchange like a Classic McEliece. This is what the Additional KE (RFC9370) facilitates for IKEv2: https://datatracker.ietf.org/doc/rfc9370/ Paul _______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-le...@ietf.org