The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Security Cryptography Whatever
Security Cryptography Whatever artwork

Standardizing Pure PQC

Security Cryptography Whatever · 2026-03-10 · 8 min

0:00--:--

Key moments - from our scoring

Substance score

7 / 100

Five dimensions, 20 points each

Insight Density2 / 20
Originality1 / 20
Guest Caliber0 / 20
Specificity & Evidence3 / 20
Conversational Craft1 / 20

The episode uses absurdist political commentary to explore genuine technical tensions in post-quantum cryptography standardization. While hybrid constructions combining ML-KEM with classical elliptic curves like X25519 are already FIPS-compatible and deployed at scale, the working group is standardizing pure PQC-only modes. The discussion touches on real concerns: whether new lattice-based algorithms like ML-KEM pose hidden risks compared to proven elliptic curves, the historical precedent of SIKE's break in Google/Cloudflare's CECPQ2b experiment, and the distinction between lattice-based schemes (ML-KEM) and other PQC families like isogenies. The episode highlights IETF process friction, including contentious consensus calls around the pure PQC draft and objections from standards participants. ML-KEM, selected through NIST's post-quantum standardization competition and designed largely by European researchers, represents the cryptographic foundation for both hybrid and pure deployments moving forward.

Key takeaways

  • →Hybrid PQC constructions (ML-KEM + X25519) are already FIPS-compliant and deployed by major browser vendors at scale, but pure ML-KEM-only modes still require standardization.
  • →The security case for pure PQC assumes post-quantum algorithms are trustworthy; hybrid modes hedge against that assumption by keeping classical ECC in the mix.
  • →ML-KEM is lattice-based and cryptographically mature relative to earlier PQC attempts like SIKE (isogeny-based), which was broken in the CECPQ2b experiment.
  • →IETF working group consensus processes around PQC standardization have faced procedural friction and competing threat models about whether hybrid or pure constructions should be the default.
  • →Major browsers will likely implement pure PQC regardless of standardization outcomes due to customer demand and the perceived quantum threat.

In this episode

  1. 1ML-KEM standardization and hybrid vs non-hybrid constructions
  2. 2FIPS compatibility and the role of X25519 in hybrid designs
  3. 3Security arguments for pure PQC versus hybrid approaches
  4. 4Historical precedent: CECPQ2b and the SIKE vulnerability
  5. 5IETF consensus process disputes and blocking objections
  6. 6Standards body jurisdiction and implementation reality

Mentioned

NISTML-KEMChromeCloudFlareX25519IETFGoogleCECPQ2bSIKENSA

Guests

Mr. Tom Riddle

Topics in this episode

Post-Quantum Cryptography (PQC)ML-KEMX25519TLSFIPSCECPQ2bSIKELattice-based cryptographyIETF TLS working groupHybrid cryptographic constructions

Questions this episode answers

Why are ML-KEM hybrids already deployed if pure PQC standardization isn't finished?

Google and Cloudflare have been running hybrid constructions combining ML-KEM with X25519 for years because hybrid mode is FIPS-compatible and provides cryptographic redundancy - the ECC component protects the connection if ML-KEM is compromised.

What's the technical difference between CECPQ2b and the pure ML-KEM standardization effort?

CECPQ2b used SIKE (isogeny-based), which was later broken; it was a hybrid experiment at an earlier PQC development stage, whereas pure ML-KEM standardization is based on lattices and a completed NIST competition.

Why would you ever use pure PQC instead of hybrid if both options exist?

Pure PQC is necessary for scenarios where elliptic curve cryptography may not be available, and some argue it's the future-proof approach once post-quantum algorithms are cryptographically validated.

Is ML-KEM a European or US algorithm?

ML-KEM was designed primarily by European researchers and selected through NIST's international post-quantum standardization competition, not developed by the NSA.

What's the main IETF process dispute around pure PQC standardization?

The episode satirizes objections to consensus calls around pure PQC drafts, with some participants arguing hybrid constructions are safer and questioning whether pure-only standardization should move forward despite prior consensus.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

2 / 20

The transcript contains almost no substantive technical content or novel insights about post-quantum cryptography standardization. The few actual technical claims (hybrid vs. non-hybrid constructions, ML-KEM security levels, FIPS compatibility) are buried under layers of absurdist political satire, name-calling, and completely off-topic tangents (Minecraft, Fortnite, Iran, GDPR cookie prompts). A B2B operator would learn virtually nothing actionable about PQC or TLS standardization.

ML-KEM has been infiltrated by the radical left.
Elon is off making data centers in space.

Originality

1 / 20

This is pure absurdist political parody with no original cryptographic thinking whatsoever. The content relies entirely on caricature (Trump/Biden/Elon parodies) and juvenile humor rather than any fresh framework, counterintuitive argument, or first-principles analysis of standardization challenges.

All right, you fools.
ML-KEM is moon math.

Guest Caliber

0 / 20

There are no actual guests with cryptographic expertise or standardization experience. The only 'guest' introduced is 'Mr. Tom' (Voldemort), a fictional Harry Potter character, presented as someone 'posting on IETF mailing lists.' This is parody, not substantive guest content.

Let me get him in here. Ground control to Mr. Tom.
He was posting on the IETF mailing lists, but the ministry keeps censoring him.

Specificity & Evidence

3 / 20

While a few technical specifics are mentioned (ML-KEM, X25519, CECPQ2b, SIKE, FIPS, 65,536-bit RSA), they appear randomly without context, explanation, or supporting data. No metrics, timelines, or concrete examples are provided to substantiate any claims. The transcript reads as technical name-dropping without depth.

The hybrid constructions have both an X25519 key and an ML-KEM key, and then the results are combined.
After Google and CloudFlare had used CECPQ2b to encrypt tens of millions of real user connections, the SIKE component of CECPQ2b was publicly ripped to shreds.

Conversational Craft

1 / 20

There is no genuine conversation or substantive questioning. The format is pure satirical dialogue with characters talking past each other, making absurd claims, and derailing into unrelated topics. No real follow-ups, no productive disagreement, no attempt to advance understanding - just political theater and jokes.

Why are you two talking about RSA? We're here to talk about pure PQC.
I can't believe we're doing this.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

hybrid13donnie8cryptography7consensus7fips6constructions6quantum5left5call5data4broken4back4algorithms4cecpq4sike4different4

Episode notes

Standardizing cryptography involves a lot of opinions. Luckily, the gamer presidents are on it. Come on, you all know the drill. This is the last time I do this. "Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@dadrian)

Full transcript

8 min

Transcribed and scored by The B2B Podcast Index.

All right, you fools. Let's finish standardizing the use of non-hybrid post quantum key exchange and TLS. I thought NIST already standardized ML-KEM at three security levels, or at least that's what some staffer told me through Mike Donilan. That's right, Joe.

But now we need to standardize how to use pure ML-KEM in TLS. I thought that was already done. Haven't those fellows at Chrome and CloudFlare been running this shit for years? It's all rolled out, Jack.

Was the hybrid construction. The key exchange contains both an X25519 key and an ML-KEM key, and then the results are combined. Fun fact, that mode is actually FIPS compatible, so long as ML-KEM is on the left, which it is. ML-KEM has been infiltrated by the radical left.

You said it yourself, Obama. God dammit, Donald. I meant that it's written as the first parameter on the left hand side of the xor when used as a FIPS compatible hybrid construction. It's the left side of the equation, not the political left.

Anyway, we still need to finish standardizing the non-hybrid constructions. If the hybrid constructions are FIPS, why would we ever need a non-hybrid construction? FIPS is woke. Donnie, I told you, if your Doge kids had cut FIPS validation, not have become a Republican.

Elon is off making data centers in space. We ran out of time to cut FIPS and iap. Besides me and Elon stopped playing Minecraft together ever since he tricked me into loading into a Minecraft version of Epstein's Island. That's fucking hilarious.

Donnie Obama. I don't get it. The hybrid constructions have more cryptography and are therefore more secure. Why are we standardizing non-hybrid constructions?

Uh, hybrid constructions are not more secure. What if the new post quantum cryptography is broken? ML-KEM is moon math. Latt are not moon math.

They're older now than elliptic curves were when they were deployed. Elliptic curves are moon math. We should all just use 65,536 bit RSA that's secure against a quantum attacker. No, it's not sleepy Joe.

Also RSA is quadratic and bit length. That's 1024 times slower than 2 0 4. Eight bit RSA. Do you really wanna wait 1024 times longer for cryptography?

Sleepy Joe. Why are you two talking about RSA? We're here to talk about pure PQC. There's plenty of use cases for non-hybrid constructions, including standards like cns, A two back, do what ML-KEM has been back do by NSA.

We need to mix in X25519 to make cryptography great again, Donnie, there's not enough bits in the parameter space of ML-KEM to have a secret key back door. Besides NSA, are the people asking to use ML-KEM on their own data? Why would they want to use a broken algorithm for their own top secret data? Nand an international competition.

ML-KEM was mostly designed by Europeans anyway, and not NSA great point, Joe. Even worse, I don't want any cryptography from the failing European Union. Their regulations are so bad that even the Olympic medals were falling apart. That is actually true.

Go look it up. The EU is just freeloading their knowledge worker class off the backs of hardworking American companies. GDPR is terrible. I do hate cookie prompts.

Anyway, uh, let's get back on topic. ML-KEM is a good algorithm and we're all gonna feel a little ridiculous if we're wasting time and compute doing elliptic curve computations once a cryptographically relevant quantum computer exists. Yeah, it's clear the future is PQC only donnie. It doesn't make sense to me that people are simultaneously so worried about the quantum threat they wanna deploy algorithms now, yet at the same time are insisting on hybrids because the new algorithms might be broken.

If you think the new algorithms might be broken, why is it important to deploy them? And this competition helps everybody hurts nobody. I was just talking to an expert and he said we can't let the crazy IETF standardize a non-hybrid. And I said, I know it's very sad.

The Democrats in the IETF are ruining cryptography in this country. Who were you talking to? It was an expert. I call him Mr.

Tom. Let me get him in here. Ground control to Mr. Tom.

Let's say Pius. What the fuck? Here it is. My good friend, Mr.

Tom Riddle spoken like a true politician. What the fuck? Donald Tom Riddle. He's Voldemort.

Where did you find Voldemort? He was posting on the IETF mailing lists, but the ministry keeps censoring him. I am being silenced for my opinions. The ministry, you mean the TLS WG chairs and the IESG?

This censorship is a continuing assault against I ETF's promise of openness. Uh, I can't believe we're doing this. The chairs refuse to acknowledge his blocking objection. Blocking objection?

Rough consensus isn't veto based. The most important objection is that using non-hybrid PQ instead of ECC plus PQ creates unnecessary security risks. After Google and CloudFlare had used CECPQ2b to encrypt tens of millions of real user connections, the SIKE component of CECPQ2b was publicly ripped to shreds. The only reason that the weakness of SIKE didn't immediately expose the CECPQ2b encrypted user data to attackers is that CECPQ2b was a hybrid with ECC.

First off, that was a completely different algorithm at a completely different stage of development seven years ago. Second, it was a different experiment that had SIKE in it. Third SIKE isn't even lattice based. It uses isogenies.

The chair has nevertheless abused their power to declare consensus on adopting the document. My objections to this consensus call, were met with a series of runarounds. No. Your complaints were completely invalid and not based in reality.

We should run a new consensus call with more clear wolves. I suggest that the current WGLC be scrapped. Why would a third consensus call have a different outcome? I was caught by surprise regarding the advanced nature of this controversial and likely harmful draft.

Bullshit. Another consensus call feels like it is only beneficial to people who didn't like the outcome of the first consensus calls. Exactly. Barack, we should get some Wikipedia admins in here.

They could clean this thread up in a Jiffy. The failing ad should address Mr. Tom's points on the record, the ad who lived come to lie. Uh, it does seem like you're abusing process and threatening integrity just because your algorithms weren't standardized.

Barack. We gotta shut this down or he'll talk his own nose off. I'm not the only person with objections. Draco.

Malfoy also objected. Your god damn student objected. This is clearly a brigade Barack. There are good people on both sides.

I booted him. Thank God you really have a quite a group chat. Donnie. You can't do that.

You can't kick out Mr. Tom. I'll see you in court. I think you mean on MODPOD.

Donnie. Wow, this was a disaster. I should start writing standards somewhere else like C2SP great idea Obama. Donnie, shouldn't you be monitoring the situation in Iran?

I am monitoring it. How do you like the performance? I thought you said you were gonna stop all Wars. Donnie, I hear Ayatollah Rasm and his cadre of fanatics are consolidating their power.

That Ayatollah thinks he's better than America. I'm gonna sock it to him in style. I'm tired of all this talk about cryptography. Let's go play Fortnite.

You guys have fun? I'm gonna go drinking with Pete Hegseth at Mar-a-Lago. You know the browsers are going to implement this no matter what. There's customer demand.

Stop doing this to yourself, Barack. Fine. Uh, let's go play Fortnite.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Episode 128: Post Quantum CryptographyThe Azure Security Podcast · on Post-Quantum Cryptography (PQC)87 / 100
  • Securing Singapore: The CSA Quantum Safe Migration FrameworkShielded · on Post-Quantum Cryptography (PQC)83 / 100
  • What CISOs Must Do Now About Quantum? | Interview with Andrew GaultSecure & Simple · on Post-Quantum Cryptography (PQC)83 / 100
  • Ep 13. Zama on the Holy Grail of AI Privacy, Fully Homomorphic EncryptionGenealogy of Cybersecurity - Startup Podcast · on Lattice-based cryptography78 / 100
  • Cyber News: Iranian Hacker, Quantum Ransomware and Rogue AIThe Audit · on Post-Quantum Cryptography (PQC)75 / 100
  • Post-Quantum Cryptography: What Every Organization Needs to Know with Michael FasuloHacker Valley Studio · on Post-Quantum Cryptography (PQC)72 / 100

More from Security Cryptography Whatever

All episodes →
  • An Odyssey of Lattice Cryptography with Mark Schultz-Wu95 / 100
  • Trump's Golden Post-Quantum EO(s)80 / 100
  • Facing the Vulnpocalypse with lcamtuf95 / 100
  • AI Finds Vulns You Can't With Nicholas Carlini100 / 100
  • Python Cryptography Breaks Up with OpenSSL with Paul Kehrer and Alex Gaynor100 / 100
Explore the best B2B Engineering & DevTools podcasts →
All Security Cryptography Whatever episodes →