On Wed, Jan 10, 2024 at 12:14 PM Bas Westerbaan <[email protected]> wrote: > > Dear tls and cfrg working groups, > > With ML-KEM (née Kyber) expected to be finalized this year, it’s time to > revisit the question of which PQ/T hybrid KEMs to standardize, and which to > recommend.
My preference would be that we use an KEM hybrid that works not just for TLS but for HPKE etc with all the parameters set. I think its fine if adapted for ML-KEM as is. Remembering which works here and which doesn't there is work that we don't need to do and if gotten wrong could cause problems. Sincerely, Watson -- Astra mortemque praestare gradatim _______________________________________________ TLS mailing list [email protected] https://www.ietf.org/mailman/listinfo/tls
