▲ | djmdjm 5 days ago | |
My understanding is that a hybrid using x25519 as the classical KEM is fine on the basis that the security of the construction rests (for the purposes of approval) on ML-KEM and can't be made worse by the other part of the hybrid algorithm. I don't have a definitive reference for this though. |