%% You should probably cite draft-usama-tls-risks-of-mlkem-04 instead of this revision. @techreport{usama-tls-risks-of-mlkem-03, number = {draft-usama-tls-risks-of-mlkem-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-usama-tls-risks-of-mlkem/03/}, author = {Muhammad Usama Sardar}, title = {{Analysis of Hybrid Key Exchange and Standalone ML-KEM in TLS 1.3}}, pagetotal = 20, year = 2026, month = jun, day = 11, abstract = {The draft presents \_symbolic\_ and \_computational\_ analysis of hybrid key exchange and standalone ML-KEM. In our observation, we believe that hybrid key exchange is preferable over standalone ML-KEM until a powerful CRQC exists which breaks *all* the bits of pre-quantum. This draft also offers opinions of the IETF participants and some preliminary discussion to help the developers and policymakers make informed choices. Finally, it offers minimal implementation guidance for hybrids.}, }