[Cryptography] Post-quantum cryptography NIST and others

Jon Callas jon at callas.org
Tue Aug 4 16:54:23 EDT 2026



> On Aug 4, 2026, at 01:08, Jacob Christian Munch-Andersen <nohat at nohatcoder.dk> wrote:
> 
> On Tue, Aug 4, 2026, at 12:29 AM, Cryptographer via cryptography wrote:
>> 
>> 
>> This site makes serious claims and proposes a patented alternative, which I think are too serious to ignore.
> 
> They are too patented to not ignore. The standards themselves are obviously dead in the water. But what a patent troll might still do is to claim that some other standard takes their ideas, and start demanding royalties. As a cryptographer, merely reading the standard poses a risk.

I think the opposite. It's a thing I recommend to people all the time -- no one is going to pay for an algorithm any more. Those days are past.

Today, patenting an algorithm means that it will be ignored, no matter how good it is. You can safely ignore it *because* it's patented. Even giving up the patents is no good, because in much of the industry, it's the scarlet P. Look at OCB mode -- the patents are all gone and it's better than any other AEAD mode. In fact, the whole history of AEAD can be summarized as people coming up with alternatives to the patents on OCB. And now? Crickets.

(And that web site is a paranoid rant that can also be ignored.)

	Jon



More information about the cryptography mailing list