Remix.run Logo
directoron an hour ago

The argument from Roberto Avanzi is reasonable: "as a codesigner of ML-KEM myself I would not trust using it exclusively: what if it gets broken mathematically and in the classical computational model (I.e. non-quantum)? Hybrid is better, and the additional time used by ECC is not significant."

tptacek an hour ago | parent [-]

A majority (but not a large majority) of cryptography engineers would use hybrids at this point, and hybrids are largely the default design for any mainstream deployment. Bernstein argument isn't "use hybrids, not pure MLKEM"; it's "MLKEM is so dangerous there shouldn't even be an informational standard saying how to use it". That's a problem, because there are non-mainstream deployment environments where you can't use hybrids.

Obviously, Bernstein is counting on you not following that level of nuance; he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.

For clarity: I am not a cryptographer; I'm a vulnerability researcher who does some cryptography work and for several reasons I talk to a lot of academic cryptographers and cryptography engineers. You could not pay me to design a PQC transport protocol for you.

fwlr 25 minutes ago | parent | next [-]

I haven’t read much of the for or against, so it’s certainly possible there’s a whole hidden web of ulterior motives at play here that I’m unaware of (rather than just “there’s a lot of pre-existing bad blood I’m unaware of, which is why both sides are snippy and pedantic”), but I feel compelled to object to this “nuance” point you make. The argument I see being made is “there is NSA pressure to document standalone MLKEM, so that there can be NSA pressure to adopt standalone MLKEM”, which seems fairly straightforward and without nuance to me.

tptacek 23 minutes ago | parent [-]

Just so we're clear, you're acknowledging that this argument hinges on the idea that documenting pure MLKEM is dangerous because, once it's documented in an (informational, optional) RFC, but only if it's documented in an RFC, NSA will pressure people to adopt it.

timschmidt 15 minutes ago | parent | next [-]

You're working real hard here to misunderstand his point and ignore historically relevant actions by NSA which have weakened and introduced attack vectors into previous standards, facilitating their adoption by orgs worldwide.

fwlr 11 minutes ago | parent | prev [-]

Absolutely, that’s more or less exactly what I took away from it.

directoron an hour ago | parent | prev [-]

Yes, the argument is MLKEM is so dangerous that it shouldn't be used alone. Even its codesigner says so. Why is it so hard to accept?

Take a look at the crypto from the 80's and 90's. They are considered bad jokes nowadays, badly designed and easily breakable. Why would the first-generation PQC algorithms be any different? Of course they're going to be broken and ridiculed in 20 years, in ways you cannot comprehend yet

tptacek an hour ago | parent [-]

I feel like what's most likely happening here, given your initial argument, is that you just learned that this is a debate about whether it should be forbidden to even document a particular MLKEM configuration, and you're now working backwards to the proposition that Bernstein is right.

To that I will only add that lattice cryptography is of approximately the same vintage as elliptic curve (both started in the late 1990s) and MLKEM is past the level of maturity relative to lattices that 25519 was relative to the original P-curves. (Correct me where I'm wrong here --- this is off the top of my head). This isn't "the first generation" of anything.

Just another nuance I think Bernstein is counting on you, the real audience for these posts, not having any intuition for.

directoron an hour ago | parent [-]

That's a weak ad hominem deflection. Readers be the judge.

tptacek an hour ago | parent [-]

In addition to noticing that your argument had moved goalposts (the part you claim is an ad hominem, but is not) I also responded substantively to a factual claim you made, and you're pretending otherwise.