A proposal to standardize the removal of Elliptic Curve Cryptography (ECC) from hybrid ECC+ML-KEM in TLS, reportedly backed by the NSA, faced significant opposition within the IETF TLS working group. One proponent of the specification was Mike Jenkins from the NSA.
During the voting period, 82 individuals on the TLS mailing list explicitly opposed the specification. Additional opposition was registered before the voting period, and some reports indicate further opposition messages were blocked. Roberto Avanzi, a co-designer of ML-KEM, stated he would not trust using ML-KEM exclusively, advocating for hybrid solutions due to potential mathematical vulnerabilities in ML-KEM.
The primary concern among opponents is the security risk associated with removing ECC. Relying solely on ML-KEM without the additional layer of ECC protection is seen as potentially risky, especially if ML-KEM were to be mathematically broken in the future. This stance contradicts some views that consider hybrid cryptography unnecessary for those with high cryptographic literacy.
Quotes from 75 of the 82 opposing individuals, along with replies to proponents' talking points, have been forwarded to the Internet Engineering Steering Group (IESG). This formal submission aims to ensure the IESG is aware of the broad consensus against the proposed specification within the IETF community.
The IETF operates on principles of open participation, transparency, and achieving broad consensus through public processes. Its activities are guided by the goal of finding the best engineering solutions for the entire internet, not just specific networks, technologies, vendors, or users. Decisions within IETF working groups are expected to reflect this consensus-driven approach.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Internet Engineering Task Force (IETF) TLS working group has largely opposed a specification, supported by the NSA, that would remove Elliptic Curve Cryptography (ECC) from hybrid ECC+ML-KEM in TLS. This opposition highlights concerns about the security implications of relying solely on ML-KEM without the added protection of ECC, particularly given the potential for future mathematical breaks in ML-KEM.