upvote
For people reading this, you may want to know the the NSA is allegedly trying to weaken hybrid ML-KEM and X25519 down to just ML-KEM. This is a good thing to pay attention to!

Here is a 6-part article about the topic: https://blog.cr.yp.to/20251004-weakened.html

reply
It’s worth noting that e.g. the Go stdlib has this hybrid construction built-in via crypto/hpke.
reply
So low not so slow
reply