| ▲ | tptacek an hour ago | |
I can think of several academic cryptographers (or rather, practitioners with doctorates) who think the hybrid/pure thing is silly. I didn't claim that a majority oppose hybrids. The point of the message he snipped from the HN thread is that pure MLKEM is not considered an unserious design by actual cryptographers (people on the HN thread --- generally not cryptographers, like me --- think it is). Cryptography engineers tend to default to hybrids. Downthread we develop more clarity about what it is Bernstein is actually in an argument about. It isn't hybrids vs. pure! | ||