On Mon, Feb 23, 2026 at 09:20:31AM +0100, Muhammad Usama Sardar wrote: > Since this draft clearly seems to be controversial, I am still failing to > see why chairs are not asking for expert review of FATT to resolve the > matter. So, I once again request the chairs to initiate FATT process. Maybe > chairs can collect all related analysis and send these pointers along with > the request.
The controversy has to do with the cryptanalytic strength of PQ-only KEMs and not much else. No formal analysis tools can address that question! Insisting on that in that context is a category error. I'm not sure what a formal analysis could possibly say about the use of one KEM or key agreement protocol or another. Formal analysis can only detect errors in how a KEM/KA is integrated into TLS 1.3, and that is not what's at issue here. Nico -- _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
