[Cryptography] NSA voting on TLS encryption at the IETF TLS WG

Nico Williams nico at cryptonector.com
Tue Jul 7 19:01:21 EDT 2026


On Tue, Jul 07, 2026 at 06:34:21PM -0400, Jon Callas wrote:
> > On Jul 3, 2026, at 10:26, Peter Fairbrother <peter at tsto.co.uk> wrote:
> > I think the title says it all - but why should the NSA be allowed to vote? Not that a vote means much here.
> 
> The NSA does not vote. [...]

Everything you say is true.

> So let's step back. Who is advocating for this? Or is this just a

Shouldn't matter.

> technical discussion about whether hybrid or solo is better and people
> who have one opinion are slinging an "NSA" accusation at people who
> have a different opinion? I'm all ears. Tell me more.

The WGLC is not about whether hybrid or non-hybrid is better.  It's
about whether to have an Internet RFC (Informational, not Proposed
Standard) documenting ML-KEM use in TLS 1.3 as RECOMMENDED=N, which
means that you get to use ML-KEM in TLS 1.3 if and when you want to, but
by default it wouldn't be used.

The whole argument boils down to two camps:

 - unreserved yes because there's ML-KEM has been studied and looks
   solid, and anyways it's more efficient than hybrids and/or CNSA 2.0
   requires it, and/or the horse left the barn anyways when the
   codepoint registry was made Specification Required decades ago

 - unreserved no because "we don't trust the NSA and friends"

Not trusting the NSA and friends is not a technical argument.  I expect
the WGLC to pass, as it should process-wise for that reason.

Nico
-- 


More information about the cryptography mailing list