Bernstein's Blog
Bernstein's Blog
Posted Dec 10, 2025 23:19 UTC (Wed) by hailfinger (subscriber, #76962)In reply to: Bernstein's Blog by farnz
Parent article: Disagreements over post-quantum encryption for TLS
This obsession with labeling some algorithm as insecure or (alternatively) not having that algorithm in a standard is really extreme.
It's structurally similar to the fight against schools teaching undesirable topics.
However, if you think that labeling algorithms as "insecure" without proof of actual insecurity is okay, then anybody may request the same labeling for RSA and any elliptic curve algorithms. You know what? That's a great idea! Let's just label all the algorithms as insecure because there is at least one person per algorithm not trusting that algorithm. Sure, that defeats the purpose of labeling in the first place. However, the debate has long since shifted from debating actual merit to forcibly preventing the opponent from entering the playing field.
