<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="mail-editor-reference-message-container">
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr; font-family: ""Aptos"", Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I wrote:</div>
<blockquote>
<div id="mail-editor-reference-message-container">
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: ""Aptos"", Arial, Helvetica, sans-serif; font-size: 11pt;">
The job of the IETF if not to pick the best and only the best. It is our job to say “if you want to do XXX here is how to do it.” And best, particularly for security, often implies trade-offs such as message size, deployment difficult, overall operating environment,
and so on.</div>
<div style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: ""Aptos"", Arial, Helvetica, sans-serif; font-size: 11pt;">
<br>
</div>
</div>
</blockquote>
<div style="color: rgb(0, 0, 0);">On 7/8/26, 5:46 PM, "Andrew Lee" <andrew@joseon.com> wrote:</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr;">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing"> Do these trade-offs include RNG leakage?</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr;">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr; font-family: ""Aptos"", Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
That’s a problem with trying to tie two different mailing lists to a changing situation: things move quickly.</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr; font-family: ""Aptos"", Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr; font-family: ""Aptos"", Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
As subsequent messages showed (at least to me and several others), there is no RNG leakage specific to using pure ML-KEM. First, the random data comes from two parties, client and server, and more importantly if you use a bad RNG in TLS, there are simpler
places to expose it If you have a bad RNG, there are other places TLS will expose it such as the plaintext server-hello random.</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr; font-family: ""Aptos"", Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr; font-family: ""Aptos"", Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
For those wishing to follow along, the full archives for the TLS working group can be found at [1]. The biggest recent thread on this will be have the subject "WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)"</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr; font-family: ""Aptos"", Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr; font-family: ""Aptos"", Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
[1] <a href="https://mailarchive.ietf.org/arch/browse/tls/" data-outlook-id="0944e22e-81ec-4147-9c4d-fe3c524afa8d">
https://mailarchive.ietf.org/arch/browse/tls/</a></div>
</div>
</body>
</html>