[openpgp] Re: I-D Action: draft-ietf-openpgp-nist-bp-comp- 00.txt
Andrew Gallagher <[email protected]> Thu, 16 Oct 2025 12:04:40 +0100
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hi, Quynh. On 16/10/2025 11:13, Quynh Dang wrote: > If it is not, the user should use ML-KEM-768 if ML-KEM-768's performance > is acceptable. If ML-KEM-768's performance is not acceptable, the user > should go with ML-KEM-512. I am confident in ML-KEM-512's security. I'm relatively unconcerned about the security properties of mlkem512. Even if the strength is weaker than claimed, it's still Pretty Good (ho ho). I'm more curious about the cost/benefit ratio of the combinatorics - are there particular applications (such as embedded controllers) where a lightweight PQ algorithm is crucial? Or is this more of a nice to have? A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]