On Mon, May 04, 2026 at 01:05:39AM +0200, Muhammad Usama Sardar wrote:
> I don't see how presenting a one-sided story helps the document progress.
> Merging the PR seems to be the constructive way forward as some of the
> opponents (at least I) will likely be willing to let it move on.

That section is titled "Why Hybrids?". There is no section "Why not
Hybrids?".

 
> As I have said, I have related formal proofs at the /symbolic/ level that
> the other two hybrid solutions are secure. Note the phrase '/could/ be
> preferred' (vs. should etc.) in the PR is a very weak statement and already
> a good middle ground. Let's merge it and move on.

Most of the issues with hybrids are stuff I would not expect formal
proofs to catch.

Key exchange in TLS 1.3 is really an exceptional case that can not be
extrapolated to pretty much anything else.




-Ilari

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to