“The problem in a nutshell. Surveillance agency NSA and its [UK counterpart] GCHQ are trying to have standards-development organizations endorse weakening [pre-quantum] ECC+PQ down to just PQ.”
Part of this is that NSA and GCHQ have been endlessly repeating arguments that this weakening is a good thing… I’m instead looking at how easy it is for NSA to simply spend money to corrupt the standardization process… The massive U.S. military budget now publicly requires cryptographic “components” to have NSA approval… In June 2024, NSA’s William Layton wrote that “we do not anticipate supporting hybrid in national security systems”…
[Later a Cisco employee wrote of selling non-hybrid cryptography to a significant customer, “that’s what they’re willing to buy. Hence, Cisco will implement it”.]
What do you do with your control over the U.S. military budget? That’s another opportunity to “shape the worldwide commercial cryptography marketplace”. You can tell people that you won’t authorize purchasing double encryption. You can even follow through on having the military publicly purchase single encryption. Meanwhile you quietly spend a negligible amount of money on an independent encryption layer to protect the data that you care about, so you’re actually using double encryption.



Quantum computers represent a complete paradigmatic. Modern quantum computers beat classical ones on some problems, while still not being able to factor some 2 digit numbers.
A single algorithm would be probable arrive some day, but why risk it right now? The Signal protocol adopted Post-Quantum some years ago. They going for a hybrid, not well tested over several years against classical computers, algorithm, would have been a security disaster.