With Real World Cryptography coming up next week, I wanted to take an opportunity to point out that our current post-quantum cryptographic primitives are not suitable for the web
Seems like the ISO processes were subverted to force weak non-NIST cryptography that didn't go through a strict multi-national competition as part of standardization
Given how bad the key recovery attack looks, we have to ask—was Classic McEliece an op to insert a backdoor into PQC? Is Classic McEliece author Dan Bernstein an NSA plant? Concerning.
eprint.iacr.org/2026/1630