[Cryptography] NSA voting on TLS encryption at the IETF TLS WG

Viktor Dukhovni cryptography at dukhovni.org
Wed Jul 8 03:25:06 EDT 2026


On Tue, Jul 07, 2026 at 06:26:20PM -0500, Nico Williams wrote:
> On Tue, Jul 07, 2026 at 06:01:21PM -0500, Nico Williams wrote:
> > Not trusting the NSA and friends is not a technical argument.  I expect
> > the WGLC to pass, as it should process-wise for that reason.
> 
> Then again, Jacob Applebaum's post to the TLS WG list just now is
> precisely the sort of technical argument against publishing that can
> cause the WGLC to fail all by itself, and may demonstrate the point
> about consensus calls not being votes.

My read on the JA post is that it is FUD[1].  ML-KEM starts with a
cryptographically strong random input `m`, whether your "system RNG"
needs a post-processing whitening step is not an ML-KEM concern.  If it
does, use a better RNG, or apply post-processing and call that your RNG.

-- 
    Viktor.  🇺🇦 Слава Україні!

[1] https://mailarchive.ietf.org/arch/msg/tls/S4DcH2U9wg_5GQMgJG3YixIty_A/


More information about the cryptography mailing list