05:46:46 I still feel that CSIDH 512 is too insecure to consider. > <@kayabanerve:matrix.org> I will drop BC1024 advocacy, switch to advocating BC512, and if CSIDH 512 is too insecure to consider, I'd likely say this discussion needs to start from zero/JAMTIS shouldn't include a PQ component. 05:48:07 I have slightly more trust in CSIDH, though, it's still quite annoying that isogenies are the only current option I could find (SWOOSH proved lattices could work, but the overhead is very nontrivial.) > <@ixr3:matrix.org> Since CSIDH might break. I will use Carrot internal forward-secrecy as first layer. Second layer Jamtis-PQ