[Cryptography] A plea to my seniors

Andrew Lee andrew at joseon.com
Fri Jul 3 01:04:26 EDT 2026


Dear Cypherpunks,

Earlier, I wrote to this list describing a battle being fought inside the IETF standards body which most of the world will never look at, but that many of you know intimately. I write, now, because I am weak, and need help from people far stronger than me. This isn't easy to admit, but what's on the line matters far more than the pride of one.

It was you all who fought the Clipper Chip. It was you who fought the export controls. You were around and active when Dr. Bernstein sued the US government and won us the right to encrypt, and then, together, you all built the encryption we actually use. You gained us private territory. That's sovereignty, and you planted the flag. I appreciate that, and of course, I know you're tired, and you've earned the right to sit this one out...

Yet, the internet has changed so much since you all kept things in check on our behalf. We've lost ground... and a lot of it. This happened on our watch, mine included, and I'm sorry for that.

Some of the responses I received to my earlier message attempted to write this off:

"Just an informational RFC."
"Just don't implement it."

They are wrong.

The Canadian government already stated on the IETF list that they will use this document to recommend solo KEM. Standards bodies across many nations have sent letters saying they are waiting for it. An informational RFC from the IETF is their green light. As we all know, every signals and intelligence agency is drooling in wait for this. Even in the event the primitives and algorithms are correct, implementations take time to harden in practice. 0days are a lot more prevalent in younger software and libraries than their more mature relatives. You don't need me to tell you the adversaries already have a handful.

The NSA is pushing solo PQ with significant fervor. The proposal has no technical merit over the hybrid already deployed. The vote [1] has failed twice and is being run a third time. Dr. Bernstein has been placed under moderation during this vote over a copyright footnote, while the oversight board simultaneously told him to make his case during the vote. NSA employees are posting from cyber.nsa.gov for the first time ever to vote yes.

I am asking you to stand up one more time.

The expertise and conviction that lives here is irreplaceable, and this fight needs you before July 8 [2].

For everyone who inherits whatever internet we leave behind.

Onwards,
Andrew

[1] Or as it's called, rough consensus sometimes calculated with singing voices [3]
[2] Details at https://nsa.2026.action.cr.yp.to/
[3] https://datatracker.ietf.org/doc/html/rfc7282


More information about the cryptography mailing list