But really, there are very few "trustworthy" PQCrypto algorithms/implementations and he is the author of more than one of those.
Has NIST stopped to recommend one winner and opted for several. Or, do these have different purposes?
Dilithium is faster but less conservative, harder to implement securely, and produces medium sigs.
FALCON is even harder to implement securely, faster to verify and produces smaller sigs, though still much larger than classical systems. IMHO this choice was questionable, in that its advantages overlap too heavily with Dilithium to be worth another standard, but NIST apparently felt otherwise.
The developers of OpenSSH agree enough to use this scheme in OpenSSH.
DJB is high profile enough that all of his stuff gets a lot of cryptanalysis from experts. This isn't a rando proposing a scheme that no one can follow, and no one can be bothered to review. He consistently designs cryptographic systems which perform better and are less error prone to implement than systems designed by committees of people.
I promise you, CRYSTALS-Kyber does not lack for expert analysis.
I ask all this because there's a pretty big "Schneier Facts" vibe to anything that involves Bernstein, and because I don't think you'll find many cryptographers --- probably even including on the NTRU Prime team --- that would sign off on his critique of Kyber and the NIST process. I could be wrong, but if I am, could you tell me how?
https://csrc.nist.gov/Projects/post-quantum-cryptography/sel...
Some previous discussion on this from 2022 and 2023:
Or simply because it was the most convenient algorithm at the time (2022).
There may also be regulated industries where Officially Approved™ algorithms need to be used, and if you're not on the list you're not going to be enabled, so if the developers of OpenSSH want to protect their users in those situations, then they're going to have to offer something on the list (even if it's not enable by default, or further down the preference ranking in the default settings).
* https://ubuntu.com/blog/ubuntu-22-04-fips-140-3-modules-avai...
* https://www.stigviewer.com/stig/canonical_ubuntu_22.04_lts/2...
* https://www.stigviewer.com/stig/red_hat_enterprise_linux_9/2...
* https://support.apple.com/en-ca/guide/certifications/apc35eb...
So in my opinion, NTRU Prime is a good cryptosystem. But it's not particularly better than Kyber: each has small advantages and disadvantages, and both got a ton of expert review (Kyber even more than NTRU Prime), and they will probably stand or fall together depending on improvements in lattice cryptanalysis.
I also don't think Kyber suffers from design-by-committee. There are a zillion small choices to make in these lattice schemes, and while some choices are definitely wrong, both the NTRU Prime and Kyber teams made reasonable ones. The same goes for SABER and regular NTRU.
Personally I think that FALCON is brilliant, but it is very difficult to securely implement or even precisely define, due to heavy use of floating-point arithmetic in the signing routine. I don't want to put words in DJB's mouth, but if you share his concern for ease of secure implementation, ease of auditing and side-channel protection, then you may prefer SPHINCS+ or, if the performance of SPHINCS+ is not acceptable in your workload, possibly Dilithium.
Of course, if signature size is make-or-break, then of the choices currently slated for standardization, FALCON has the smallest signatures. But it is possible that the new signature onramp will change that in a few years -- if you can be confident in the security of whatever is chosen within so short a time.