2026-06-27
Link: https://www.youtube.com/watch?v=qPhoJQtvgUo
HN Discussion: 2 points, 0 comments
Daniel J. Bernstein is one of the few cryptographers whose name belongs in the same sentence as the algorithms securing the modern internet. He gave us Curve25519, Ed25519, ChaCha20-Poly1305, and qmail. He sued the U.S. government in the 1990s to publish cryptographic source code as protected speech — and won. When djb decides a public fight is worth having, that fight tends to matter.
The title here signals exactly such a fight. The post-quantum TLS transition is one of the most consequential cryptographic migrations in internet history, and the choices being made now — which lattice schemes get standardized, what hybrid constructions are mandated, which parameter sets are considered acceptable — will be baked into TLS libraries, browsers, and HSMs for the next two decades. Bernstein has been publicly skeptical for years of how NIST's post-quantum process has weighted certain candidates (notably Kyber/ML-KEM) against alternatives like NTRU and his own Classic McEliece, and he has been vocal about what he sees as opaque parameter-strength claims and conflicts of interest within the standardization process.
A talk framed as "the push to weaken post-quantum TLS" almost certainly covers some combination of:
This is the kind of content that gets two upvotes at 9 AM and then sinks, because livestream links don't aggregate karma well and "post-quantum TLS standardization politics" doesn't have the snap of a benchmark or a startup launch. But anyone who ships TLS, runs a CA, designs an HSM, or simply cares whether the encryption protecting their bank transfers in 2035 is sound should care what djb has to say here. He has been right about cryptographic standards being weakened before — Dual_EC_DRBG is the obvious historical example — and the cost of ignoring him then was catastrophic.
