Get the latest tech news
Bugs happen: The easy way to compare solo PQ to ECC+PQ
What's better: upgrading an ECC-based protocol to ECC+PQ, or switching it to solo PQ? Here's the simplest way to see that solo PQ will be an inexcusable security disaster: Some examples of what I've said about this before: I gave a 2016 talk recommending ECC+PQ, and I've been consistently recommending ECC+PQ since then. In 2018, I described the NIST post-quantum competition as "the largest regression ever in the quality of cryptographic software"; I said this "will not be easy to fix".
None
Or read this on Hacker News

