2026-03-12 07:19 UTC
”Cryspen’s Approach to TLS: A Critical Analysis” https://symbolic.software/blog/2026-03-07-cryspen-tls/ - I feel less confident about OpenSSH’s ML-KEM libcrux approach now
Replies (2)
-
@jas@fosstodon.org 2026-03-12 07:33
“verification theatre” - https://eprint.iacr.org/2026/192
-
@kpcyrd@chaos.social 2026-03-12 14:18
@jas@fosstodon.org It looks like there have been rustsec advisories (RUSTSEC-2026-00{23,24,25,26}), but only one of them has a severity of 'high', the other ones have a severity of 'none'. Anybody can send pull requests to the advisory-db, maybe the author of the blogpost could add to them and adjust the impact/severity/description/title. Note also (by @djc@hachyderm.io): https://github.com/cryspen/libcrux/issues/1335