logoalt Hacker News

tptacektoday at 3:39 AM3 repliesview on HN

A majority (but not a large majority) of cryptography engineers would use hybrids at this point, and hybrids are largely the default design for any mainstream deployment. Bernstein argument isn't "use hybrids, not pure MLKEM"; it's "MLKEM is so dangerous there shouldn't even be an informational standard saying how to use it". That's a problem, because there are non-mainstream deployment environments where you can't use hybrids.

Obviously, Bernstein is counting on you not following that level of nuance; he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.

For clarity: I am not a cryptographer; I'm a vulnerability researcher who does some cryptography work and for several reasons I talk to a lot of academic cryptographers and cryptography engineers. You could not pay me to design a PQC transport protocol for you.


Replies

fwlrtoday at 4:24 AM

I haven’t read much of the for or against, so it’s certainly possible there’s a whole hidden web of ulterior motives at play here that I’m unaware of (rather than just “there’s a lot of pre-existing bad blood I’m unaware of, which is why both sides are snippy and pedantic”), but I feel compelled to object to this “nuance” point you make. The argument I see being made is “there is NSA pressure to document standalone MLKEM, so that there can be NSA pressure to adopt standalone MLKEM”, which seems fairly straightforward and without nuance to me.

show 1 reply
directorontoday at 3:45 AM

Yes, the argument is MLKEM is so dangerous that it shouldn't be used alone. Even its codesigner says so. Why is it so hard to accept?

Take a look at the crypto from the 80's and 90's. They are considered bad jokes nowadays, badly designed and easily breakable. Why would the first-generation PQC algorithms be any different? Of course they're going to be broken and ridiculed in 20 years, in ways you cannot comprehend yet

show 1 reply
rasengantoday at 6:16 AM

> A majority (but not a large majority) of cryptography engineers would use hybrids at this point

Actually, based on the WGLC, or the three of them rather, it's pretty clear that Ph.D cryptographers significantly prefer hybrid over pure ML-KEM.

> he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.

The brigade by the NSA (6+ votes or more if you include NSA contractors), the AD being former NSA and the moderation of Dr. Bernstein for a footnote seems pretty fair and balanced </sic>.

Meanwhile, the lead of the EU PQC program, professors from several universities, Ph.Ds and, additionally, legendary cryptographers all expressed significant concern and even stronger opposition to the publishing of the draft.

Finally, the chairs refused to share their methodology in determining consensus when asked by several Professors and Ph.Ds.

show 1 reply