<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body style="overflow-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;">Dear Rich,<br id="lineBreakAtBeginningOfMessage"><div><br><blockquote type="cite"><div>On Jul 8, 2026, at 12:46 PM, Salz, Rich via cryptography <cryptography@metzdowd.com> wrote:</div><br class="Apple-interchange-newline"><div>

<meta http-equiv="Content-Type" content="text/html; charset=utf-8">

<div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
<br>
</div>
<div id="mail-editor-reference-message-container">
<div class="ms-outlook-mobile-reference-message skipProofing">
<meta name="Generator" content="Microsoft Exchange Server">
</div>
<div class="ms-outlook-mobile-reference-message skipProofing">On 7/8/26, 3:24 PM, "cryptography" <cryptography-bounces+rsalz=akamai.com@metzdowd.com> wrote:</div>
<ul data-editing-info="{"applyListStyleFromLevel":false,"unorderedStyleType":4}" style="margin-top: 0px; margin-bottom: 0px;">
<li style="font-size: 11pt; margin-top: 0px; margin-bottom: 0px; list-style-type: "➢ ";">
<div class="ms-outlook-mobile-reference-message skipProofing" role="presentation">
Example list of those opposing publication:</div>
</li><li style="font-size: 11pt; margin-top: 0px; margin-bottom: 0px; list-style-type: "➢ ";">
<div role="presentation" style="direction: ltr; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif;">
...</div>
</li><li style="font-size: 11pt; margin-top: 0px; margin-bottom: 0px; list-style-type: "➢ ";">
<div class="ms-outlook-mobile-reference-message skipProofing" role="presentation">
Example list of those supporting publication:</div>
</li><li style="font-size: 11pt; margin-top: 0px; margin-bottom: 0px; list-style-type: "➢ ";">
<div class="ms-outlook-mobile-reference-message skipProofing" role="presentation" style="direction: ltr; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif;">
...</div>
</li></ul>
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
<br>
</div>
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
Once again, Andrew unfairly summarizes to make his point.  Those who agree with him have their academic titles posted, those who don’t are smeared with things like “NSA Employee” as if we should a priori be scared of them. He couches them by saying “Example
 list” as if that adds credibility to their independence. This tactic becomes tiresome really quickly.</div>
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
<br>
</div>
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
Why doesn’t the example list of those who support publication include</div>
<ul data-editing-info="{"applyListStyleFromLevel":false,"unorderedStyleType":2}" style="direction: ltr; margin-top: 0px; margin-bottom: 0px;">
<li style="font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt; direction: ltr; margin-top: 0px; margin-bottom: 0px; list-style-type: "- ";">
<div role="presentation" style="direction: ltr; margin-top: 0px; margin-bottom: 0px;">
Soatok, noted cryptographer (at laest on social media)</div>
</li><li style="font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt; direction: ltr; margin-top: 0px; margin-bottom: 0px; list-style-type: "- ";">
<div role="presentation" style="direction: ltr; margin-top: 0px; margin-bottom: 0px;">
Sophie Schmieg, noted cryptographer</div>
</li><li style="font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt; direction: ltr; margin-top: 0px; margin-bottom: 0px; list-style-type: "- ";">
<div role="presentation" style="direction: ltr; margin-top: 0px; margin-bottom: 0px;">
David Benjamin, world-class implementor of BoringSSL and others</div>
</li><li style="font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt; direction: ltr; margin-top: 0px; margin-bottom: 0px; list-style-type: "- ";">
<div role="presentation" style="direction: ltr; margin-top: 0px; margin-bottom: 0px;">
Scott Fluhrer, security developer/cryptographer</div>
</li><li style="font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt; direction: ltr; margin-top: 0px; margin-bottom: 0px; list-style-type: "- ";">
<div role="presentation" style="direction: ltr; margin-top: 0px; margin-bottom: 0px;">
Richard Barnes, co-author of various HPKE drafts (and the original ACME draft)</div>
</li><li style="font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt; direction: ltr; margin-top: 0px; margin-bottom: 0px; list-style-type: "- ";">
<div role="presentation" style="direction: ltr; margin-top: 0px; margin-bottom: 0px;">
John Mattson, security architect at Ericsson</div>
</li></ul>
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
and so on.  (I would not put myself on that list, but I was a cypherpunk until the trolls took over, supported John Young regularly, and never worked for the NSA or Google.)</div>
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
<br></div></div></div></div></blockquote><div><br></div><div>Fair point. Let me fix it:</div><div><br></div><div>Example list of those against publication:</div><div>Ph.D Professor (co-creator of Ed25519, X25519, creator of chachapoly1305, etc. used by most)</div><div>Ph.D Professor (co-creator of Ed25519, X25519, former co-lead of EU PQ)</div><div>Ph.D (formal analysis author used in TLS WG FATT for this process)</div><div>Ph.D Professor (coauthored successful attacks on SHA-1)</div><div>Ph.D (team leader of EU PQ)</div><div>Ph.D (core Tor developer)</div><div><br></div><div>Example list of those in favor of publication: </div><div>Dr. Sophie Schmieg (Google)</div><div>David Benjamin (Google) [1]</div><div>Scott Fluhrer (CISCO) [1]</div><div>Richard Barnes (CISCO) [1]</div><div>John Mattsson (Ericsson) [1]</div><div><br></div><div>[1] Could not find any verification on academic titles.</div><div><br></div><div>To help the in favor publication side, I refrained from putting NSA, GCHQ, Canadian Cyber Centre, etc., names.</div><div><br></div><blockquote type="cite"><div><div><div id="mail-editor-reference-message-container"><div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
</div>
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
The job of the IETF if not to pick the best and only the best. It is our job to say “if you want to do XXX here is how to do it.” And best, particularly for security, often implies trade-offs such as message size, deployment difficult, overall operating environment,
 and so on.</div>
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
<br></div></div></div></div></blockquote><div><br></div>Do these trade-offs include RNG leakage?</div><div><br></div><div>Best,</div><div>Andrew</div><div><br><blockquote type="cite"><div><div><div id="mail-editor-reference-message-container"><div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
</div>
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: "&quot;Aptos&quot;", Arial, Helvetica, sans-serif; font-size: 11pt;">
<br>
</div>
</div>
</div>

_______________________________________________<br>The cryptography mailing list<br>cryptography@metzdowd.com<br>https://www.metzdowd.com/mailman/listinfo/cryptography<br></div></blockquote></div><br></body></html>