> There's an argument that it's worth building in a 256-bit cipher for quantum > resistance. Not clear that AES-256 is the best 256-bit cipher though.
Yes, I get that. "not clear" is a highly uncompelling argument, tho. _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls