A [non-hybrid tls-mlkem] standard by any other name: How IETF evades responsibility for its actions
Summary
The article criticizes the IETF for evading responsibility in its handling of the non-hybrid TLS-ML-KEM standard, focusing on the organization's accountability in cryptographic standardization.
Similar Articles
On Accountability
A reflective essay on the lack of accountability in software engineering and LLM development, drawing from a keynote at ICST 2024 that called for responsibility akin to other engineering fields.
The State of Post-Quantum Cryptography
A detailed overview of the ongoing transition to post-quantum cryptography, covering NIST's standardization of ML-KEM and ML-DSA, the 'harvest now, decrypt later' threat, hybrid key exchange adoption, and the fragmentation of PKI into MTC and X.509 with ML-DSA.
Ignore DNSSEC if you like MITM attacks
The article argues that ignoring DNSSEC exposes users to man-in-the-middle attacks, using examples from email, Matrix, and XMPP, and draws a parallel to the historical resistance against HTTPS.
NSA and IETF: Fairness
NSA and IETF address fairness in internet standards and protocols.
Trust, but Don't Verify: Epistemic Blind Spots in LLM Source Evaluation
This paper identifies a failure mode in LLMs where they do not verify the validity of numerical statistics when synthesizing multiple sources, instead relying on the stylistic markers of analytical rigor. The authors term this 'epistemic alignment' and show that it persists across models and domains, resisting prompting-based mitigations.