> There's an argument that it's worth building in a 256-bit cipher for quantum 
> resistance. Not clear that AES-256 is the best 256-bit cipher though.

Yes, I get that.

"not clear" is a highly uncompelling argument, tho.
_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to