TechNewsReel
Live

Cryptographer Daniel J. Bernstein Reports Widespread Opposition to PQC Hybrid Spec

A dispute between the IETF and the NSA over post-quantum cryptography standards sees dozens of experts voice opposition to a proposed TLS specification.

TechNewsReel Newsroom · August 15, 2026

Cryptographer Daniel J. Bernstein has reported significant pushback against a proposed post-quantum cryptography (PQC) hybrid specification within the Internet Engineering Task Force (IETF). The dispute highlights an ongoing tension between independent security researchers and the standards-setting body over the influence of the National Security Agency (NSA).

In a blog post published August 14, 2026, Bernstein stated that 82 individuals expressed "unambiguous opposition" to the specific PQC hybrid specification on the TLS mailing list during its voting period. This development is the ninth installment in a series of critiques by Bernstein regarding the relationship between the NSA and the IETF, focusing on how cryptographic standards are developed and adopted.

The PQC Transition

The conflict arises from the global effort to transition to post-quantum cryptography, a move designed to protect digital communications from future quantum computers capable of breaking current encryption. To mitigate the risk of adopting unproven new algorithms, the IETF has considered a "hybrid" approach. This method combines classical cryptography, such as Elliptic Curve Cryptography (ECC), with PQC. In theory, a hybrid system remains secure as long as at least one of the two combined methods remains unbroken.

However, Bernstein has consistently argued that certain proposed hybrid specifications are flawed. He contends that these standards may be influenced by the NSA in ways that introduce unnecessary security risks, potentially undermining the very protections they are meant to provide.

Systemic Implications

The stakes are high because the IETF's Transport Layer Security (TLS) standards govern the encryption of nearly all web traffic. Because TLS is the bedrock of internet privacy, the adoption of a flawed cryptographic specification could introduce systemic vulnerabilities into the global infrastructure. Such weaknesses could potentially allow state actors or other sophisticated adversaries to decrypt private communications on a massive scale.

Future Outlook

While the report of 82 opposing voices indicates a lack of consensus among the technical community, the final status of the specification remains a point of contention. Observers are watching to see whether the IETF will adjust the specification to address these security concerns or proceed with the current version despite the documented opposition from the mailing list. The outcome will likely signal how the IETF balances government agency input against the critiques of the independent cryptographic community.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.