[TLS] Re: Response to CoI Complaints

Nico Williams <[email protected]> Fri, 17 Jul 2026 15:50:19 -0500
Newsgroups gmane.ietf.tls
Message-ID <alqVi6af8+t/CMrd@ubby>
On Fri, Jul 17, 2026 at 03:51:32PM -0400, Daniel Apon wrote:
> I am happy, of course, to discuss the technical issue about hashing that
> Jacob has brought up. I will summarize that here:

My reply up-thread listed _my_ thinking on the matter.  The summary is
that because we don't have a practical PQDH we're just always going
to have an `m`-like RNG leak from the server to the client in any KEM we
choose to use, and it would be nice to know we're not using Dual_EC, but
obviously that's not easy to ascertain.  Thus I think all KEMs should
come with a statement that one should use DRBGs/RNGs that are not
Dual_EC-like.

> [...]
> 
> However, one should clearly see how benign the entire thing is. [...]

I'm sure the justification was bening.  That is not my concern.

> I am very happy to chat about the technical matter; I'm interested in this
> too!

Well, you can find my post up-thread or see the above summary.

> On the other hand, while I am "required" to engage with the TLS WG mailing
> list as a part of my professional duties at my job, I am not "required" to
> engage with [...]

Eh, I'm not asking you to.  And I myself have conveyed how annoying that
mode of argument is.  But now you're replying to me.

Nico
-- 

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]