| ▲ | eis an hour ago | |
I'm confused by your messages linked by DJB. You say that better cryptographers would not choose hybrids, which seems to say that you should indeed think that hybrids are not a good choice. Then you say you are not such a good cryptographer and would choose a hybrid. But if you know that more senior cryptographers think they are not the right choice then why choose them anyways? Or am I misreading "cryptography-literate" here? Can you explain a bit more regarding your statement that DJB's POV on the matter has no broad support amongst his peers? I'm not in the field but Bernstein seemed like a highly respected member with a long track record in the crypto community, at least from the outside. Do you think the community is wrong or is it DJB who's wrong and why? There's also a good chance that I totally missed the argument being made. | ||
| ▲ | tptacek an hour ago | parent [-] | |
I can think of several academic cryptographers (or rather, practitioners with doctorates) who think the hybrid/pure thing is silly. I didn't claim that a majority oppose hybrids. The point of the message he snipped from the HN thread is that pure MLKEM is not considered an unserious design by actual cryptographers (people on the HN thread --- generally not cryptographers, like me --- think it is). Cryptography engineers tend to default to hybrids. Downthread we develop more clarity about what it is Bernstein is actually in an argument about. It isn't hybrids vs. pure! | ||