http://lpoaj76nfopd5lpinbskyqtroppamrzhhay3g4vvjm75st6ger34lbyd.onion/posts/2024/03/news.html
They appear to believe that, the way they are doing it, it is more secure than Signal's implementation , as (according to their claims, unlike Signal) their implementation does not break the double ratchet's self-healing properties. However, they also base their choice of KEM (sntrup761 rather than Kyber) on djb's post , whose line of argumentation has been criticised, particularly the claim that NIST calculated the attack costs on Kyber wrongly (although to our knowledge there is at least...