[Cryptography] NSA voting on TLS encryption at the IETF TLS WG

Salz, Rich rsalz at akamai.com
Wed Jul 8 21:33:30 EDT 2026



I wrote:
The job of the IETF if not to pick the best and only the best. It is our job to say “if you want to do XXX here is how to do it.” And best, particularly for security, often implies trade-offs such as message size, deployment difficult, overall operating environment, and so on.

On 7/8/26, 5:46 PM, "Andrew Lee" <andrew at joseon.com> wrote:

      Do these trade-offs include RNG leakage?

That’s a problem with trying to tie two different mailing lists to a changing situation: things move quickly.

As subsequent messages showed (at least to me and several others), there is no RNG leakage specific to using pure ML-KEM.  First, the random data comes from two parties, client and server, and more importantly if you use a bad RNG in TLS, there are simpler places to expose it If you have a bad RNG, there are other places TLS will expose it such as the plaintext server-hello random.

For those wishing to follow along, the full archives for the TLS working group can be found at [1]. The biggest recent thread on this will be have the subject "WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)"

[1] https://mailarchive.ietf.org/arch/browse/tls/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://www.metzdowd.com/pipermail/cryptography/attachments/20260709/6544a9f0/attachment.htm>


More information about the cryptography mailing list