Bernstein's Blog
Bernstein's Blog
Posted Dec 9, 2025 14:31 UTC (Tue) by chris_se (subscriber, #99706)In reply to: Bernstein's Blog by muase
Parent article: Disagreements over post-quantum encryption for TLS
What I can say though is the following: on the substance of hybrid vs. pure I'm fully on dbj's side here. I cannot fathom the reasoning why anyone would want to standardize a pure PQC algorithm at this point in time. There has been _extensive_ cryptoanalysis on both RSA and EC, and we can be quite confident that they will not be broken by classical computers during any of our lifetimes. While there has been a lot of cryptoanalysis done on PQC algorithms especially in the last years, they have not yet been vetted even remotely as well as classical algorithms. Look at the amount of PQC algorithm candidates proposed by extremely knowledgeable and intelligent people that have since been broken to such an extent that they aren't an obstacle to even a classical computer. This gives me a lot of pause in relying _solely_ on a PQC algorithm.
I think it's great that we are now already thinking about PQC because at some point someone will build a capable enough quantum computer. But until that happens, I think it's grossly negligent to switch to a pure PQC algorithm _at this point in time_, because until then we will be sure that the classical algorithm will provide the necessary guarantees, even if the specific PQC algorithm is broken.
