Bugs happen: The easy way to compare solo PQ to ECC+PQ(blog.cr.yp.to) |
Bugs happen: The easy way to compare solo PQ to ECC+PQ(blog.cr.yp.to) |
ECC software can have flaws too but I don't think anyone seriously suggested hybridizing two different ECC implementations, for example.
Additionally, NIST had the foresight to derandomize all the algorithms, so we can now check e.g. what a correct implementation will produce on particular seeds. This is a big deal because a bunch of e.g. ECDSA bugs, such as biased nonces or reused nonces, are trivally caught by such tests/derandomization.
TLDR: the bugs are going to be elsewhere.
Software bugs is a weak argument for a new hybrid standard, and doesn't justify the additional complexity.