Filippo Valsorda :go: on Nostr: In which I argue that we should pick P-256 + ML-KEM-768 as the one true hybrid, ...
In which I argue that we should pick P-256 + ML-KEM-768 as the one true hybrid, reducing implementer workload and attack surface.
Thing is, P-256 is actually very pleasant to implement these days. The world changed compared to ten years ago.
https://mailarchive.ietf.org/arch/msg/tls/n_jM_bRZN8DM7SnpBMGA6SqpD6Q/
Thing is, P-256 is actually very pleasant to implement these days. The world changed compared to ten years ago.
https://mailarchive.ietf.org/arch/msg/tls/n_jM_bRZN8DM7SnpBMGA6SqpD6Q/