[openpgp] Re: I-D Action: draft-ietf-openpgp-nist-bp-comp- 00.txt

Andrew Gallagher <[email protected]> Thu, 16 Oct 2025 12:04:40 +0100
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hi, Quynh.

On 16/10/2025 11:13, Quynh Dang wrote:
> If it is not, the user should use ML-KEM-768 if ML-KEM-768's performance 
> is acceptable.  If ML-KEM-768's performance is not acceptable, the user 
> should go with ML-KEM-512. I am confident in ML-KEM-512's security.

I'm relatively unconcerned about the security properties of mlkem512. 
Even if the strength is weaker than claimed, it's still Pretty Good (ho 
ho). I'm more curious about the cost/benefit ratio of the combinatorics 
- are there particular applications (such as embedded controllers) where 
a lightweight PQ algorithm is crucial? Or is this more of a nice to have?

A

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]