upvote
The “technical arguments” are documented here: https://blog.cr.yp.to/20260221-structure.html
reply
And those technical arguments are quite thorough, covering both the pro and the contra arguments.
reply
That document is nonsense? The current RFC is not to say

> use pure ML-KEM > hybrid ML-KEM.

the current document is instead to say

> If you are in a setting where you REALLY want to use pure ML-KEM (though we explicitly recommend you do not do it), this is the standard you would implement against.

It is also technically inaccurate. The whole argument hinges on it being negligible cost in all environments to do hybrids. This is explicitly false. See this message on the TLS-WG on explicitly this point

https://mailarchive.ietf.org/arch/msg/tls/_9i3uIVDQ3pDRswpm9...

A large list of pros/cons detailing a question that isn't being debated that is technically inaccurate is what I would expect from an LLM, not from a competent cryptographer. I am unsurprised to see it from DJB given his behavior in the last decade regarding PQC.

reply