On Sat, Apr 04, 2026 at 09:30:16PM +0100, Stephen Farrell wrote:

> I do agree it might help move matters along though if the
> TLS WG reached consensus that deploying hybrids is the BCP
> for the present. I don't think we've established that, have
> we? Have we even been asked the question?

I keep trying to ask the question, and as it seems that use of hybrids
remains the prudent best/current practice, I don't see a barrier to
reaching "rough" consensus on that question.

Recent theoretical progress on reducing the resource requirements
(logical qbits, and circuit sizes, i.e. gate counts and time) for
breaking 256-bit ECC with Shor's algorithm, may have reduced the
perceived value of the ECC components of hybrids for some QC "optimists"
who were betting on CRQC's to show up in O(decade), but now think it may
much sooner than previously expected.

So support for hybrid may be slightly more tepid this month than last,
but I still expect it to be possible to find a rough consensus along
those lines.

-- 
    Viktor.  🇺🇦 Слава Україні!

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to