| ▲ | tptacek an hour ago | |
Just so we're clear, you're acknowledging that this argument hinges on the idea that documenting pure MLKEM is dangerous because, once it's documented in an (informational, optional) RFC, but only if it's documented in an RFC, NSA will pressure people to adopt it. | ||
| ▲ | timschmidt an hour ago | parent | next [-] | |
You're working real hard here to misunderstand his point and ignore historically relevant actions by NSA which have weakened and introduced attack vectors into previous standards, facilitating their adoption by orgs worldwide. | ||
| ▲ | fwlr an hour ago | parent | prev [-] | |
Absolutely, that’s more or less exactly what I took away from it. | ||