Re: [TLS] ML-KEM key agreement for TLS 1.3

2024-03-14 Thread Sophie Schmieg
h of the message was > > incorrect. This alert is used for errors where the message does > > not conform to the formal protocol syntax. This alert should > > never be observed in communication between proper implementations, > > except when mess

Re: [TLS] [CFRG] X-Wing: the go-to PQ/T hybrid KEM?

2024-01-11 Thread Sophie Schmieg
learn from X-Wing, but not try to chop them to fit > into that one keyhole, as it were. > > > ___ > TLS mailing list > TLS@ietf.org > https://www.ietf.org/mailman/listinfo/tls > -- Sophie Schmieg | I

Re: [TLS] What is the TLS WG plan for quantum-resistant algorithms?

2023-11-08 Thread Sophie Schmieg
> > On 8 Nov 2023, at 8:34, Loganaden Velvindron wrote: > > > > I support moving forward with hybrids as a proactively safe deployment > > option. I think that supporting > > only Kyber for KEX is not enough. It would make sense to have more options. > > > > Google uses NTRU HRSS internally: > >