The cr.yp.to blog
2026.08.14: NSA and IETF, part 9: An update. #pqcrypto #hybrids #nsa #ietf #procedures
Back in June, I saw that NSA and its minions had called and were packing an IETF vote on standardizing a specification of how to remove the ECC seatbelt from hybrid ECC+ML-KEM in TLS. For example, one vote for the spec was from NSA's Mike Jenkins, who had never sent email to the TLS mailing list before. I responded by calling for volunteers to speak up on the public-interest side.
I'm happy to report that 82 people spoke up on the TLS mailing list in unambiguous opposition to this spec during the voting period. There were also some additional people (Izzy Grosof, for example, and Ivan Visconti) who had already registered opposition before the voting period; I've heard credible reports of further opposition messages being blocked by the chairs; and, even though this wasn't filed as opposition, it was good to see the following statement from Roberto Avanzi: "as a codesigner of ML-KEM myself I would not trust using it exclusively: what if it gets broken mathematically and in the classical computational model (I.e. non-quantum)? Hybrid is better, and the additional time used by ECC is not significant."
(In the opposite direction, I've been pointed to the following claim from Thomas Ptacek: "The more cryptography-literate you are, the more likely it is you think hybrids are silly." Oh, well, I guess that settles it then.)
For 75 of the 82 people with opposition statements on the list during this voting period, I see no way that anyone can even try arguing that anything in their messages suggests the possibility of spec modifications removing the objections. I've taken quotes from those 75 people and forwarded them to "IESG", the Internet Engineering Steering Group, along with my replies to talking points from spec proponents. Copies of my messages to IESG: 1, 2, 3, 4.
The rest of this blog post says what's supposed to happen, what has happened so far, and what's likely to happen next.
What's supposed to happen?
Here's what IETF says: "IETF participation is free and open to all interested individuals. ... IETF activities are conducted with extreme transparency, in public forums. Decision-making requires achieving broad consensus via these public processes. ... Fundamentally, 'IETF participants use their best engineering judgment to find the best solution for the whole Internet, not just the best solution for any particular network, technology, vendor, or user.' "
IETF work is divided across "working groups" (WGs). Here's what IETF says about WG decisions: "The general rule on how Working Groups make decisions is that the Working Group has to come to 'rough consensus', meaning that a very large majority of those who care must agree, and that those in the minority have had a chance to explain why and their points have been addressed, even if they were not agreed with."
... continue reading