2 comments
I used to be pro-hybrid but I feel much more on the fence about it nowadays.<p>ECC software can have flaws too but I don't think anyone seriously suggested hybridizing two different ECC implementations, for example.
Why don't we use hybrid RSA and ECC then? Or hybrid AES and ChaCha20?<p>Software bugs is a weak argument for a new hybrid standard, and doesn't justify the additional complexity.