Bernstein's Blog
Bernstein's Blog
Posted Dec 9, 2025 21:55 UTC (Tue) by ballombe (subscriber, #9523)In reply to: Bernstein's Blog by chris_se
Parent article: Disagreements over post-quantum encryption for TLS
You forget the more likely:
6. The NSA wants the new standard to require major change in sensitive code paths so that they can exploit bugs in the implementation independently of the strength of PQC.
