Obviously, Bernstein is counting on you not following that level of nuance; he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.
For clarity: I am not a cryptographer; I'm a vulnerability researcher who does some cryptography work and for several reasons I talk to a lot of academic cryptographers and cryptography engineers. You could not pay me to design a PQC transport protocol for you.
Take a look at the crypto from the 80's and 90's. They are considered bad jokes nowadays, badly designed and easily breakable. Why would the first-generation PQC algorithms be any different? Of course they're going to be broken and ridiculed in 20 years, in ways you cannot comprehend yet
To that I will only add that lattice cryptography is of approximately the same vintage as elliptic curve (both started in the late 1990s) and MLKEM is past the level of maturity relative to lattices that 25519 was relative to the original P-curves. (Correct me where I'm wrong here --- this is off the top of my head). This isn't "the first generation" of anything.
Just another nuance I think Bernstein is counting on you, the real audience for these posts, not having any intuition for.
Actually, based on the WGLC, or the three of them rather, it's pretty clear that Ph.D cryptographers significantly prefer hybrid over pure ML-KEM.
> he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.
The brigade by the NSA (6+ votes or more if you include NSA contractors), the AD being former NSA and the moderation of Dr. Bernstein for a footnote seems pretty fair and balanced </sic>.
Meanwhile, the lead of the EU PQC program, professors from several universities, Ph.Ds and, additionally, legendary cryptographers all expressed significant concern and even stronger opposition to the publishing of the draft.
Finally, the chairs refused to share their methodology in determining consensus when asked by several Professors and Ph.Ds.
What's noteworthy about the last list of sponsors of his position that Dan Bernstein posted was how few of them were cryptographers.
The great Dr. Orr Dunkelman was admirably vocal in his opposition to the publishing of this draft.
I am. I literally hold six patents around secure key generation and management. I stand by DJB's points.
Can you explain a bit more regarding your statement that DJB's POV on the matter has no broad support amongst his peers? I'm not in the field but Bernstein seemed like a highly respected member with a long track record in the crypto community, at least from the outside. Do you think the community is wrong or is it DJB who's wrong and why? There's also a good chance that I totally missed the argument being made.
Downthread we develop more clarity about what it is Bernstein is actually in an argument about. It isn't hybrids vs. pure!
Peter Duesberg, a Ph.D. in molecular biology / retrovirology who taught at Berkley and was a member of the National Academy, who maintained that HIV does not cause AIDS and that antiretroviral drugs do more harm than good.
Walter Freeman, M.D. academic neurologist and first chair of neurology at George Washington University who believed that severing frontal-lobe connections could stabilize personality and stop pathological cycles of thought.
Charles B. Davenport, Ph.D. in biology, geneticist and founder of the Eugenics Record Office.
Henry H. Goddard, Ph.D. in psychology, intelligence-testing researcher and later professor of abnormal psychology who believed intellectual disability, poverty, prostitution, and criminality constituted a hereditary family type.
Clarence Cook Little, Harvard Ph.D., mammalian geneticist and prominent cancer researcher who insisted for years that the evidence did not establish a causal relationship between smoking and lung cancer.
Fun game. We could laugh at all of them, and your examples too, if not for the damage they caused.