[Cryptography] NSA voting on TLS encryption at the IETF TLS WG
Nico Williams
nico at cryptonector.com
Tue Jul 7 19:01:21 EDT 2026
On Tue, Jul 07, 2026 at 06:34:21PM -0400, Jon Callas wrote:
> > On Jul 3, 2026, at 10:26, Peter Fairbrother <peter at tsto.co.uk> wrote:
> > I think the title says it all - but why should the NSA be allowed to vote? Not that a vote means much here.
>
> The NSA does not vote. [...]
Everything you say is true.
> So let's step back. Who is advocating for this? Or is this just a
Shouldn't matter.
> technical discussion about whether hybrid or solo is better and people
> who have one opinion are slinging an "NSA" accusation at people who
> have a different opinion? I'm all ears. Tell me more.
The WGLC is not about whether hybrid or non-hybrid is better. It's
about whether to have an Internet RFC (Informational, not Proposed
Standard) documenting ML-KEM use in TLS 1.3 as RECOMMENDED=N, which
means that you get to use ML-KEM in TLS 1.3 if and when you want to, but
by default it wouldn't be used.
The whole argument boils down to two camps:
- unreserved yes because there's ML-KEM has been studied and looks
solid, and anyways it's more efficient than hybrids and/or CNSA 2.0
requires it, and/or the horse left the barn anyways when the
codepoint registry was made Specification Required decades ago
- unreserved no because "we don't trust the NSA and friends"
Not trusting the NSA and friends is not a technical argument. I expect
the WGLC to pass, as it should process-wise for that reason.
Nico
--
More information about the cryptography
mailing list