Mike Osborne at IBM research would be a good one to get a brain dump from on that effort

I'm also curious about the feasibility of zk-STARKs, as they are hash based and should have good PQ properties

note - no concerns if this draft punts the ecdh side and no one picks it up as a separate draft

Speaking as someone who managed to get themselves in trouble by not quite getting this right (in particular, by failing to properly define the allowable ephemeral key types), having this fully specified would have helped me not get in quite as much trouble.

if long term storage is a concern are you considering techniques that deal with store now attacks similar to https://bughunters.google.com/blog/5108747984306176/google-s-threat-model-for-post-quantum-cryptography

jinling Zhang, Welcome to the IETF

general question - is this more protocol oriented - is oauth a better home?

