Unlikely that signatures will ever be hybrid.
Fairly likely we move off of hybrid for key exchange once NIST finishes standardization.
Fairly likely we move off of hybrid for key exchange once NIST finishes standardization.
Jokes aside, it would be interesting to have your optimistic take on the current PQ security trajectory. Do you think that it has proven comparably secure to ECC? Or just that by the time PQ primitives are ready to be rolled out they'll be load bearing enough that it is better to use them solo rather than the added overhead/complexity of a hybrid?
Signatures are very difficult to do hybrid in a way that's not strippable.
I think lattices are in the realm of boring crypto these days, but I ask the actual mathematical cryptographers when I need real opinions.