Bernstein's Blog
Bernstein's Blog
Posted Dec 10, 2025 9:47 UTC (Wed) by farnz (subscriber, #17727)In reply to: Bernstein's Blog by Wol
Parent article: Disagreements over post-quantum encryption for TLS
It's trivial for the algorithm to be named something like "experimental_insecure_pqc_algoname" (e.g. "experimental_insecure_NTRU_enc") in the standard, and to reserve a number for it. Then, if it's later determined to be secure, it can have the name "pqc_algoname" (e.g. "NTRU_encrypt"), with "experimental_insecure_pqc_algoname" as a deprecated alias for it.
If a PHB then says "our crypto is stronger because we use experimental_insecure_NTRU_enc", then they're likely to have regulators and other PHBs alike point out their error.
