Bernstein's Blog
Bernstein's Blog
Posted Dec 9, 2025 11:43 UTC (Tue) by muase (subscriber, #178466)In reply to: Bernstein's Blog by hDF
Parent article: Disagreements over post-quantum encryption for TLS
In the mailing lists, there were several occasions where he tried to derail the discussion with weird arguments, going so far that other colleagues accused him of spreading FUD. There were multiple occasions where he repeatedly failed to explain his positions in a sound way (aka they simply didn't make much sense), and instead of clarifying he tried to derail the discussion instead. Quite a bit of his PQC criticism is more of a minority opinion, and not necessarily consensus/status quo in the cryptographic community.
All in all it can be said that during PQC-standardization, Bernstein repeatedly did not argue in good faith – that doesn't necessarily mean that he's wrong; but readers should be aware of that.
Links:
https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/S...
https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/G...
https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/C...
https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W...
There are others; but those are the most-prominent ones I remember that caused the WTF-moments here.
