[Cryptography] NSA voting on TLS encryption at the IETF TLS WG

Peter Fairbrother peter at tsto.co.uk
Wed Jul 8 18:42:47 EDT 2026


On 08/07/2026 08:25, Viktor Dukhovni wrote:

> 
> My read on the JA post is that it is FUD[1].  ML-KEM starts with a
> cryptographically strong random input `m`, whether your "system RNG"
> needs a post-processing whitening step is not an ML-KEM concern.  If it
> does, use a better RNG, or apply post-processing and call that your RNG.


Hmm, I can't agree.

I don't know enough about ML-KEM to comment on whether removing 
whitening from the "m" input breaks anything, but afaict we are talking 
about a standard method of implementation. Subsequently having to add 
parts to a standard is neither approved nor wise nor universally 
implemented.


Also we know for 100% sure that NSA like to backdoor "standardised" RNG's.



Peter Fairbrother

Security is hard, and usually ill-defined.

Of course there is still the ninth Law - "Security is a Boolean" - but 
people don't take enough notice of that.




More information about the cryptography mailing list