|
|
|
|
|
by mswphd
21 days ago
|
|
that's really not possible for ML-KEM. They took a well-known "boring" design, and tweaked certain internal sub-components of it. Their tweaks were good, and their analysis/exposition of it were good. So they deserve to win. But there were many essentially identical schemes (e.g. Saber and New Hope are essentially the same as ML-KEM). To infiltrate/compromise ML-KEM, then NSA would need to do something like 1. corrupt some europeans for the literal submission, and 2. corrupt the competing submissions, which are substantially similar, and 3. corrupt the entirety of the cryptographic community so they miss a flaw in the (extremely simple tbh) 2011 paper htat kicked off hte design. If a conspiracy requires corrupting a single person it's plausible. ML-KEM being intentionally weakend by the NSA would quite literally require corrupting like 100+ different people in different countries. it makes no sense. |
|