[TLS] Re: Improving the quality of the discussion on the TLS email list

[email protected] Thu, 30 Jul 2026 17:50:40 -0700
Newsgroups gmane.ietf.tls
Message-ID <[email protected]>
--===============6564392036496953847==
Content-Type: multipart/alternative;
 boundary=Apple-Mail-5B35E89B-F2F0-4FA8-B937-116566B5BD8F
Content-Transfer-Encoding: 7bit


--Apple-Mail-5B35E89B-F2F0-4FA8-B937-116566B5BD8F
Content-Type: multipart/related;
	type="text/html";
	boundary=Apple-Mail-BCB793CB-0196-4C4A-BE88-87910BB86FCD
Content-Transfer-Encoding: 7bit


--Apple-Mail-BCB793CB-0196-4C4A-BE88-87910BB86FCD
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi=
v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D=
"auto">Hi Paul,<div><br></div><div>Both drafts have a =E2=80=9Crecommended t=
o implement=E2=80=9D flag, where the hybrid draft is =E2=80=9CY=E2=80=9D and=
 the other draft is =E2=80=9CN=E2=80=9D. I believe the intention is for impl=
ementers to look at these flags. It appears to me to be easier to understand=
 than several paragraphs of LLM output, but that=E2=80=99s just my perspecti=
ve.&nbsp;</div><div><br></div><div>Your usage of =E2=80=9Cdowngrade=E2=80=9D=
 along the lines of Python versions is also confusing. There=E2=80=99s the o=
bvious point (that Sophie referred to) that downgrade is a term of art in cr=
yptography, eg has a very specific meaning in the field.</div><div><br></div=
><div>Ignoring that, your usage remains confusing. The natural point of comp=
arison would have the hybrid scheme as the =E2=80=9Cearlier version=E2=80=9D=
 scheme. It is a transitional scheme while we gain confidence in MLKEM. If h=
umanity is ever able to create a cryptographically relevant quantum computer=
, it will have additional overhead for no benefit, and should be deprecated s=
hortly thereafter.</div><div><br></div><div>Note that what you call a =E2=80=
=9CFeynman estimate=E2=80=9D is not due to Feynman. Physicists instead call t=
his technique a =E2=80=9CFermi Estimate=E2=80=9D, after Enrico Fermi.&nbsp;<=
/div><div><br></div><div><div style=3D"display: block;" class=3D""><div styl=
e=3D"-webkit-user-select: all; -webkit-user-drag: element; display: inline-b=
lock;" class=3D"apple-rich-link" draggable=3D"true" role=3D"link" data-url=3D=
"https://en.wikipedia.org/wiki/Fermi_problem"><a style=3D"border-radius:10px=
;font-family:-apple-system, Helvetica, Arial, sans-serif;display:block;-webk=
it-user-select:none;width:300px;user-select:none;-webkit-user-modify:read-on=
ly;user-modify:read-only;overflow:hidden;text-decoration:none;" class=3D"lp-=
rich-link" rel=3D"nofollow" href=3D"https://en.wikipedia.org/wiki/Fermi_prob=
lem" dir=3D"ltr" role=3D"button" draggable=3D"false" width=3D"300"><table st=
yle=3D"table-layout:fixed;border-collapse:collapse;width:300px;background-co=
lor:#E6E6E6;font-family:-apple-system, Helvetica, Arial, sans-serif;" class=3D=
"lp-rich-link-emailBaseTable" cellpadding=3D"0" cellspacing=3D"0" border=3D"=
0" width=3D"300"><tbody><tr><td vertical-align=3D"center"><table bgcolor=3D"=
#E6E6E6" cellpadding=3D"0" cellspacing=3D"0" width=3D"300" style=3D"table-la=
yout:fixed;font-family:-apple-system, Helvetica, Arial, sans-serif;backgroun=
d-color:rgba(230, 230, 230, 1);-apple-color-filter:initial;" class=3D"lp-ric=
h-link-captionBar"><tbody><tr><td style=3D"padding:8px 0px 8px 0px;" class=3D=
"lp-rich-link-captionBar-textStackItem"><div style=3D"max-width:100%;margin:=
0px 16px 0px 16px;overflow:hidden;" class=3D"lp-rich-link-captionBar-textSta=
ck"><div style=3D"word-wrap:break-word;font-weight:500;font-size:12px;overfl=
ow:hidden;text-overflow:ellipsis;text-align:left;" class=3D"lp-rich-link-cap=
tionBar-textStack-topCaption-leading"><a rel=3D"nofollow" href=3D"https://en=
.wikipedia.org/wiki/Fermi_problem" style=3D"text-decoration: none" draggable=
=3D"false"><font color=3D"#000000" style=3D"color: rgba(0, 0, 0, 1);">Fermi p=
roblem</font></a></div><div style=3D"word-wrap:break-word;font-weight:400;fo=
nt-size:11px;overflow:hidden;text-overflow:ellipsis;text-align:left;" class=3D=
"lp-rich-link-captionBar-textStack-bottomCaption-leading"><a rel=3D"nofollow=
" href=3D"https://en.wikipedia.org/wiki/Fermi_problem" style=3D"text-decorat=
ion: none" draggable=3D"false"><font color=3D"#A2A2A9" style=3D"color: rgba(=
60, 60, 67, 0.6);">en.wikipedia.org</font></a></div></div></td><td style=3D"=
padding:6px 12px 6px 0px;" class=3D"lp-rich-link-captionBar-rightIconItem" w=
idth=3D"30"><a rel=3D"nofollow" href=3D"https://en.wikipedia.org/wiki/Fermi_=
problem" draggable=3D"false"><img style=3D"pointer-events:none !important;di=
splay:inline-block;width:30px;height:30px;border-radius:3px;" width=3D"30" h=
eight=3D"30" draggable=3D"false" class=3D"lp-rich-link-captionBar-rightIcon"=
 alt=3D"wikipedia.png" src=3D"cid:593C86C9-9902-4D00-A139-4C20B85AC11A"></a>=
</td></tr></tbody></table></td></tr></tbody></table></a></div></div><br></di=
v><div>This is a minor point. At the same time, it does not raise my confide=
nce in the rest of the content of your messages.&nbsp;</div><div><br></div><=
div>Best,</div><div><br></div><div>Mark</div><div><br id=3D"lineBreakAtBegin=
ningOfSignature"><div dir=3D"ltr">Sent from my iPhone</div><div dir=3D"ltr">=
<br><blockquote type=3D"cite">On Jul 30, 2026, at 2:31=E2=80=AFPM, Paul Rome=
r &lt;[email protected]&gt; wrote:<br><br></blockquote></div>=
<blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<span>Sophie (if I may):=
</span><br><span></span><br><span>I have been puzzled by your emphasis on do=
wngrade attacks. I never</span><br><span>mentioned them. I'll offer a conjec=
ture below about why you emphasize</span><br><span>them.</span><br><span></s=
pan><br><span>To focus on what I actually said, start with this sentence fro=
m the</span><br><span>security considerations section of draft-ietf-tls-mlke=
m-09.txt:</span><br><span></span><br><span> &nbsp;&nbsp;&nbsp;Implementers m=
ust evaluate their specific security, performance, and</span><br><span> &nbs=
p;&nbsp;&nbsp;operational constraints when deciding whether to deploy standa=
lone</span><br><span> &nbsp;&nbsp;&nbsp;ML-KEM or a hybrid construction.</sp=
an><br><span></span><br><span>The simplest claim that I make is that the TLS=
 Working Group should</span><br><span>try to give accurate, decision-relevan=
t information to people who have</span><br><span>to choose what to deploy.</=
span><br><span></span><br><span></span><br><span># Costs and Benefits</span>=
<br><span>Let MLKEM768 and X25519MLKEM768 be the two protocols under</span><=
br><span>consideration. The natural way to think about the choice between th=
em</span><br><span>is to make one the baseline and assess the costs and bene=
fits of a</span><br><span>switch to the other. All that matters for the deci=
sion is the cost and</span><br><span>benefit of the change.</span><br><span>=
</span><br><span>Take X25519MLKEM768 as the baseline. Consider the costs and=
 benefits</span><br><span>of a downgrade to MLKEM768 (where I am using the w=
ord _downgrade_ in</span><br><span>the same way that someone speaks of a dow=
ngrade from Python 3.13 to</span><br><span>3.12).</span><br><span></span><br=
><span>One of the benefits of the downgrade is that MLKEM768 does not need t=
o</span><br><span>devote any CPU time to the elliptic curve calculations of X=
25519. Mr.</span><br><span>Jager claimed that this benefit was negligible. M=
s. Connolly implied</span><br><span>that it not negligible because X25519 ta=
kes twice as much CPU time as</span><br><span>MLKEM768.</span><br><span></sp=
an><br><span>The simple point I made is that taking as given this factor of 2=
, the</span><br><span>data cited by Ms. Connolly show that the cycle counts f=
or both X25519</span><br><span>and MLKEM768 are so small that they are negli=
gible.</span><br><span></span><br><span>I did not consider the reduction in t=
he data that is exchanged because</span><br><span>neither Mr. Jager nor Ms. C=
onnolly mentioned the cost of exchanging</span><br><span>data. Moreover, we k=
now that the change in the data required is just</span><br><span>64 bytes.</=
span><br><span></span><br><span>To emphasize that only a change in quantitie=
s belongs in a</span><br><span>cost-benefit calculation, consider an upgrade=
 from MLKEM768 to</span><br><span>X25519MLKEM768. It does not matter how muc=
h data is exchanged in the</span><br><span>base case (which now is MLKEM768.=
) Nor does it make sense to consider</span><br><span>the percentage increase=
 in the data exchanged because of the upgrade</span><br><span>to X25519MLKEM=
768. It isn't possible to attach a value to a percentage</span><br><span>or r=
atio that lack units. It is possible to value on a reduction in</span><br><s=
pan>the data that must be exchanged.</span><br><span></span><br><span>In the=
 same way, we can put a value on some quantity of CPU seconds.</span><br><sp=
an>The data in the table that Ms. Connolly cites show that the downgrade</sp=
an><br><span>to MLKEM768 will save roughly 1.1 * 10^(-4) CPU seconds per TLS=
 1.3</span><br><span>connection. I converted this into dollars and compared i=
t to an</span><br><span>estimate of the cost in dollars of the forgone secur=
ity:</span><br><span></span><br><span>- Benefit from downgrading:</span><br>=
<span> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;B =3D $2.9 * 10^(-9) per TLS 1.3 connection</span><br><span><=
/span><br><span>- Cost of downgrading:</span><br><span> &nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C =3D $2.7 * 10^(-=
4) per TLS 1.3 connection</span><br><span></span><br><span>I do not claim th=
at my estimates of B and C are definitive. I</span><br><span>encouraged othe=
rs to come up with alternative estimates.</span><br><span></span><br><span>W=
hat I did claim was that if the discussion in this group focused on</span><b=
r><span>specifics such as these, consensus would emerge naturally, just as i=
t</span><br><span>does in science.</span><br><span></span><br><span>But now w=
e have a puzzle. Why is this suggestion about doing a</span><br><span>cost-b=
enefit analysis perceived as such a threat?</span><br><span></span><br><span=
></span><br><span># Why You Keep Referring to Downgrade Attacks</span><br><s=
pan></span><br><span>Sophie, my conjecture is that you keep referring to the=
 impossibility</span><br><span>of downgrade attacks because you want to clai=
m that no one is forced</span><br><span>to use MLKEM768. Let's stipulate tha=
t. Everyone is free to choose.</span><br><span>Does this imply that making M=
LKEM768 a standard will not do any harm?</span><br><span>No. If that argumen=
t were correct, it would also apply to a standard</span><br><span>that calls=
 for no encryption of a TLS connection. Moreover, a large</span><br><span>li=
terature on standards debunks the assertion that in a context where</span><b=
r><span>many standards can emerge, free choice automatically supports an</sp=
an><br><span>efficient outcome.</span><br><span></span><br><span>But set all=
 that aside. As a response to what I wrote, any defense of</span><br><span>t=
he decision to bless MLKEM768 is off point. I was very explicit about</span>=
<br><span>refraining from saying anything about whether or not it was good o=
r</span><br><span>bad to formalize MLKEM768. I focused on the specific quest=
ion I</span><br><span>highlighted above: Given that there are people who hav=
e to decide what</span><br><span>to deploy, what can we offer to help them m=
ake an informed decision?</span><br><span></span><br><span>Here we hit the p=
uzzle again. Why is the suggestion that the group</span><br><span>provide in=
formation about B and C perceived as a threat?</span><br><span></span><br><s=
pan></span><br><span># The TLS Working Group Is in a Hole</span><br><span></=
span><br><span>I think I understand why the message I submitted made people w=
ho</span><br><span>supported publication of the RFC feel defensive and threa=
tened. I</span><br><span>think everyone understands why.</span><br><span></s=
pan><br><span>Hostility toward something as innocuous as a cost-benefit anal=
ysis is</span><br><span>a sign of the damage that was done by the strategy o=
f misdirection and</span><br><span>deception that was used to get the RFC pu=
blished. If we accept that</span><br><span>the RFC would inevitably have bee=
n published, it would be have been</span><br><span>better for the group to h=
ave stated that it was publishing it because</span><br><span>government offi=
cials want it and that interested parties should ask</span><br><span>them wh=
y they wanted it.</span><br><span></span><br><span>The strategy that was use=
d instead has leave the group in a hole. The</span><br><span>choice it can m=
ake is to climb out or keep digging.</span><br><span></span><br><span>The wa=
y to climb out is to copy the only social system that has ever</span><br><sp=
an>delivered voluntary consensus, the system of science. The strategy of</sp=
an><br><span>science may sometimes cause discomfort, but it is simple. Focus=
</span><br><span>attention on specific bits of evidence that help resolve a p=
recisely</span><br><span>formulated question. Make contributions public. Use=
 a proof of work to</span><br><span>filter out cheap talk.</span><br><span><=
/span><br><span></span><br><span>On Tue, Jul 28, 2026 at 6:14=E2=80=AFPM Sop=
hie Schmieg</span><br><span>&lt;[email protected]&gt; w=
rote:</span><br><blockquote type=3D"cite"><span></span><br></blockquote><blo=
ckquote type=3D"cite"><span>It seems like the point you want to make, when c=
ondensed to be more succinctly is that compute overhead of the handshake its=
elf might be so small that a factor of three does not constitute a major ove=
rhead. Indeed the cost of compute overhead tends to vary substantially betwe=
en network architectures, with bandwidth usually far outweighing the cost of=
 compute. However, this is not the case for all networks, in particular conn=
ections within a datacenter are usually compute constrained, not network lat=
ency constrained. Deidre's point that there are situations where the hybrid h=
as non-negligible overhead is therefore simply true, at least for some use c=
ases.</span><br></blockquote><blockquote type=3D"cite"><span></span><br></bl=
ockquote><blockquote type=3D"cite"><span>But more importantly, this question=
 is beside the point. Key exchange algorithms in TLS are negotiated in a dow=
ngrade protected manner, and with current stacks preferring (usually exclusi=
vely) hybrids over pure, the cost or lack thereof of a hybrid is not an obje=
ction that should be seen as material to standardization to begin with. So t=
he good news is that all your TLS connections will continue to use a hybrid,=
 without you having to pay a dime, with zero risk of a downgrade. You do not=
 even having to change your TLS configuration, as the hybrid is, as noted, d=
efault in all relevant stacks. When using Chrome, you can check by hitting F1=
2 and looking at the security tab, where it should state which key exchange a=
lgorithm was negotiated. Unless you deliberately change the defaults, and fi=
nd a server which will offer pure ML-KEM, this will always read X25519MLKEM7=
68. Similar functionality exists in other browsers, too, and they too go wit=
h X25519MLKEM768 unless specifically configured otherwise by yourself.</span=
><br></blockquote><blockquote type=3D"cite"><span></span><br></blockquote><b=
lockquote type=3D"cite"><span>The algorithm choices are part of the key deri=
vation function call, and so cannot be modified by an attacker without eithe=
r forging a signature or having the participants notice and subsequently fai=
l the handshake (an attacker with the power to modify traffic can always cau=
se the handshake to fail, so this is not a DOS vector).</span><br></blockquo=
te><blockquote type=3D"cite"><span></span><br></blockquote><blockquote type=3D=
"cite"><span>As for conduct on the mailing list, my personal preference woul=
d be the usage of smaller messages, especially when discussing overhead :). T=
his means that when using an LLM to draft a message, it is usually more effi=
cient to just send the prompt, instead of the usually fairly verbose output o=
f the LLM.</span><br></blockquote><blockquote type=3D"cite"><span></span><br=
></blockquote><blockquote type=3D"cite"><span>On Tue, Jul 28, 2026 at 2:16=E2=
=80=AFPM Paul Romer &lt;[email protected]&gt; wrote:</span><b=
r></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></s=
pan><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=
=3D"cite"><span>I started reading messages on the TLS list several weeks ago=
 after a</span><br></blockquote></blockquote><blockquote type=3D"cite"><bloc=
kquote type=3D"cite"><span>blog post by Daniel Bernstein surfaced on Hacker N=
ews calling</span><br></blockquote></blockquote><blockquote type=3D"cite"><b=
lockquote type=3D"cite"><span>attention to the then-pending decision about w=
hether to publish</span><br></blockquote></blockquote><blockquote type=3D"ci=
te"><blockquote type=3D"cite"><span>"ML-KEM Post-Quantum Key Agreement for T=
LS 1.3" as an RFC.</span><br></blockquote></blockquote><blockquote type=3D"c=
ite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><b=
lockquote type=3D"cite"><blockquote type=3D"cite"><span>On the basis of what=
 I read, I concluded that my status as a newcomer</span><br></blockquote></b=
lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>would di=
squalify me from participating in that decision. I withheld my</span><br></b=
lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><=
span>comments until the decision was made.</span><br></blockquote></blockquo=
te><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></bl=
ockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><s=
pan>I share the concern that many members voice: the group discussion is</sp=
an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span>dysfunctional. I'm writing now because I fear that suggestions a=
bout</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquo=
te type=3D"cite"><span>how to do better are not informed by an accurate diag=
nosis of the</span><br></blockquote></blockquote><blockquote type=3D"cite"><=
blockquote type=3D"cite"><span>problem and that the measures being considere=
d will make the</span><br></blockquote></blockquote><blockquote type=3D"cite=
"><blockquote type=3D"cite"><span>underlying problem worse.</span><br></bloc=
kquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><spa=
n></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote=
 type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote>=
<blockquote type=3D"cite"><blockquote type=3D"cite"><span># 1. Science as th=
e Model for How To Reach a Consensus</span><br></blockquote></blockquote><bl=
ockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquo=
te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Th=
e oral tradition I absorbed as an undergraduate included a</span><br></block=
quote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span=
>description of science that was attributed to Enrico Fermi: "Science</span>=
<br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"=
cite"><span>is a process for reaching consensus." At the time, I vigorously<=
/span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote ty=
pe=3D"cite"><span>disagreed. This description seemed to open the door to all=
 kinds of</span><br></blockquote></blockquote><blockquote type=3D"cite"><blo=
ckquote type=3D"cite"><span>unscientific ways to reach a consensus. But over=
 time, I've come to</span><br></blockquote></blockquote><blockquote type=3D"=
cite"><blockquote type=3D"cite"><span>appreciate it, provided we make explic=
it the assumption that consensus</span><br></blockquote></blockquote><blockq=
uote type=3D"cite"><blockquote type=3D"cite"><span>is voluntary. I'd rephras=
e it as:</span><br></blockquote></blockquote><blockquote type=3D"cite"><bloc=
kquote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;**Science is=
 the only social system that has ever achieved broad</span><br></blockquote>=
</blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>conse=
nsus without coercion.**</span><br></blockquote></blockquote><blockquote typ=
e=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockqu=
ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Billions of pe=
ople share a consensus that the earth is a spheroid, not</span><br></blockqu=
ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>a=
 flat disk. To be sure, there are deniers. There are always deniers.</span><=
br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c=
ite"><span>But the consensus among billions is astonishing.</span><br></bloc=
kquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><spa=
n></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote=
 type=3D"cite"><span>My diagnosis of the problems with the TLS Working Group=
 draws on my</span><br></blockquote></blockquote><blockquote type=3D"cite"><=
blockquote type=3D"cite"><span>understanding of how scientists reach consens=
us.</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquot=
e type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span>A. Participants agree on two principl=
es:</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquot=
e type=3D"cite"><span> &nbsp;&nbsp;&nbsp;- Evidence is the ultimate arbiter o=
f truth.</span><br></blockquote></blockquote><blockquote type=3D"cite"><bloc=
kquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;- There are objective rules fo=
r logical inference.</span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote>=
<blockquote type=3D"cite"><blockquote type=3D"cite"><span>B. In their discou=
rse, scientists exchange several types of "good" messages:</span><br></block=
quote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span=
> &nbsp;&nbsp;&nbsp;1. Good messages almost always focus on specifics that a=
llow a</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockq=
uote type=3D"cite"><span>direct connection to evidence.</span><br></blockquo=
te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &=
nbsp;&nbsp;&nbsp;2. Some good messages contribute new evidence and use logic=
 to</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquot=
e type=3D"cite"><span>summarize the implications of the augmented body of ev=
idence.</span><br></blockquote></blockquote><blockquote type=3D"cite"><block=
quote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;3. Other good messages challeng=
e misstatements about the evidence</span><br></blockquote></blockquote><bloc=
kquote type=3D"cite"><blockquote type=3D"cite"><span>cited by others.</span>=
<br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"=
cite"><span> &nbsp;&nbsp;&nbsp;4. Still other good messages uncover flaws in=
 the logic used to</span><br></blockquote></blockquote><blockquote type=3D"c=
ite"><blockquote type=3D"cite"><span>draw implications from the available ev=
idence.</span><br></blockquote></blockquote><blockquote type=3D"cite"><block=
quote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;5. When someone contributes a m=
essage that is subsequently shown</span><br></blockquote></blockquote><block=
quote type=3D"cite"><blockquote type=3D"cite"><span>to be false or misleadin=
g, this contributor sends a particularly</span><br></blockquote></blockquote=
><blockquote type=3D"cite"><blockquote type=3D"cite"><span>important type of=
 follow-up message that acknowledges the flaws in the</span><br></blockquote=
></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>cont=
ributor's message and recognizes the accuracy of the analysis by</span><br><=
/blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"=
><span>others.</span><br></blockquote></blockquote><blockquote type=3D"cite"=
><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><block=
quote type=3D"cite"><blockquote type=3D"cite"><span>The striking thing about=
 this list is that although it has many</span><br></blockquote></blockquote>=
<blockquote type=3D"cite"><blockquote type=3D"cite"><span>talented members, i=
t receives few good messages. In what follows, I'll</span><br></blockquote><=
/blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>give s=
pecific examples, of missing messages: a message of type 2 and a</span><br><=
/blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"=
><span>message of type 4 that no one sent even though there surely were</spa=
n><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span>members who understood the points that these two messages conve=
y.</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote=
 type=3D"cite"><span>Because no one responded, an error persisted.</span><br=
></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cit=
e"><span></span><br></blockquote></blockquote><blockquote type=3D"cite"><blo=
ckquote type=3D"cite"><span>More moderation will not get you the messages th=
at this list needs.</span><br></blockquote></blockquote><blockquote type=3D"=
cite"><blockquote type=3D"cite"><span>The missing messages suggest that a co=
ncern about what is permitted</span><br></blockquote></blockquote><blockquot=
e type=3D"cite"><blockquote type=3D"cite"><span>may already be encouraging p=
eople to self-censor. There are too many</span><br></blockquote></blockquote=
><blockquote type=3D"cite"><blockquote type=3D"cite"><span>messages that con=
tribute noise, but there are safer ways to limit the</span><br></blockquote>=
</blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>harm t=
hey do.</span><br></blockquote></blockquote><blockquote type=3D"cite"><block=
quote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br><=
/blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"=
><span># 2. Specifics</span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote>=
<blockquote type=3D"cite"><blockquote type=3D"cite"><span>Participants in sc=
ientific discussions focus doggedly on narrow</span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>assertions a=
bout specifics. This is how the community sustains its</span><br></blockquot=
e></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>com=
mitment to the principle that evidence is the ultimate arbiter of</span><br>=
</blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite=
"><span>truth.</span><br></blockquote></blockquote><blockquote type=3D"cite"=
><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><block=
quote type=3D"cite"><blockquote type=3D"cite"><span>In that spirit, I will f=
ocus on a specific email exchange from</span><br></blockquote></blockquote><=
blockquote type=3D"cite"><blockquote type=3D"cite"><span>February 2026 that c=
onsists of an assertion and a response. Both are</span><br></blockquote></bl=
ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>specific e=
nough that one can assess whether they are accurate and on</span><br></block=
quote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span=
>point.</span><br></blockquote></blockquote><blockquote type=3D"cite"><block=
quote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span>On 27 February 2026, Tibor Jage=
r wrote:</span><br></blockquote></blockquote><blockquote type=3D"cite"><bloc=
kquote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;"the use of h=
ybrid crypto comes with negligible overhead,</span><br></blockquote></blockq=
uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;=
&nbsp;as for ML-KEM + ECC."</span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>https://mail=
archive.ietf.org/arch/msg/tls/4PcWkID3bs4M_-He_OL0jy5CyZY/</span><br></block=
quote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span=
></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t=
ype=3D"cite"><span>That same day, Deirdre Connolly replied:</span><br></bloc=
kquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><spa=
n></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote=
 type=3D"cite"><span> &nbsp;&nbsp;&nbsp;"X25519 is almost twice as slow as M=
LKEM768 (</span><br></blockquote></blockquote><blockquote type=3D"cite"><blo=
ckquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;https://blog.cloudflare.com/p=
q-2025/#ml-kem-versus-x25519)"</span><br></blockquote></blockquote><blockquo=
te type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></b=
lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>https://=
mailarchive.ietf.org/arch/msg/tls/dSP0hWuwt_zVuMhZmGpMmftPJS4/</span><br></b=
lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><=
span></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockqu=
ote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote typ=
e=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockqu=
ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span># 3. Red Herri=
ngs and Intent</span><br></blockquote></blockquote><blockquote type=3D"cite"=
><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><block=
quote type=3D"cite"><blockquote type=3D"cite"><span>According to Wikipedia, a=
 red herring misleads or distracts from a</span><br></blockquote></blockquot=
e><blockquote type=3D"cite"><blockquote type=3D"cite"><span>relevant or impo=
rtant question. Someone can inject a red herring</span><br></blockquote></bl=
ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>intention=
ally or inadvertently.</span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote>=
<blockquote type=3D"cite"><blockquote type=3D"cite"><span>Section 4 gives an=
 example of a message of type 4 that finds fault</span><br></blockquote></bl=
ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>with the l=
ogic of the response by Ms. Connolly. It shows that her</span><br></blockquo=
te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>re=
sponse is a red herring. A simple arithmetic argument shows that the</span><=
br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c=
ite"><span>factor of 2 that she cites has zero bearing on the assertion by M=
r.</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote=
 type=3D"cite"><span>Jager.</span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Section 5 ha=
s a message of type 2 that adds new evidence, in this</span><br></blockquote=
></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>case=
, evidence drawn from the source that Ms. Connolly cites. This new</span><br=
></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cit=
e"><span>evidence supports Mr. Jager's assertion.</span><br></blockquote></b=
lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><=
br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c=
ite"><span>Under the norms of science, the appropriate response to a red her=
ring</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquo=
te type=3D"cite"><span>is to show how it misleads and correct it. This does n=
ot require any</span><br></blockquote></blockquote><blockquote type=3D"cite"=
><blockquote type=3D"cite"><span>discussion about the intent of the person w=
ho contributed it. In fact,</span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span>it would be a huge mistake to r=
espond by launching an inquisition into</span><br></blockquote></blockquote>=
<blockquote type=3D"cite"><blockquote type=3D"cite"><span>intent. The red he=
rring has already derailed the work of the group. An</span><br></blockquote>=
</blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>inqui=
ry into intent compounds the damage by wasting time and energy</span><br></b=
lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><=
span>that should be devoted to the work of the group, agreeing on specific</=
span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ=
e=3D"cite"><span>assertions that are true.</span><br></blockquote></blockquo=
te><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></bl=
ockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><s=
pan>One clear sign of the dysfunction in this group is the many emails</span=
><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span>devoted to a discussion of intent. It is easy to understand the=
 appeal</span><br></blockquote></blockquote><blockquote type=3D"cite"><block=
quote type=3D"cite"><span>of a system of moderation that could filter them o=
ut, but there are</span><br></blockquote></blockquote><blockquote type=3D"ci=
te"><blockquote type=3D"cite"><span>other possible responses, including the l=
ighter touch of social</span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span>pressure that discourages contributio=
ns that are off point. In section</span><br></blockquote></blockquote><block=
quote type=3D"cite"><blockquote type=3D"cite"><span>6, "Reaching Consensus",=
 I suggest another way to filter out cheap</span><br></blockquote></blockquo=
te><blockquote type=3D"cite"><blockquote type=3D"cite"><span>talk: require t=
he author to use evidence and logic to reach a</span><br></blockquote></bloc=
kquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>conclusion a=
nd ignore any messages that do not live up to this</span><br></blockquote></=
blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>standar=
d. This is an instance of what has come to be known as proof of</span><br></=
blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite">=
<span>work.</span><br></blockquote></blockquote><blockquote type=3D"cite"><b=
lockquote type=3D"cite"><span></span><br></blockquote></blockquote><blockquo=
te type=3D"cite"><blockquote type=3D"cite"><span>One advantage of this parti=
cular type of proof of work is that it</span><br></blockquote></blockquote><=
blockquote type=3D"cite"><blockquote type=3D"cite"><span>respects the sharp d=
istinction that must be drawn between a good</span><br></blockquote></blockq=
uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>message that s=
ays "these facts and logic show that your assertion is</span><br></blockquot=
e></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>wro=
ng" and a bad message that says "many of us don't like what you are</span><b=
r></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"ci=
te"><span>saying so please stop saying it."</span><br></blockquote></blockqu=
ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></b=
lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><=
span>The way to get someone to stop making an assertion is to marshal</span>=
<br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"=
cite"><span>evidence and logic which show that it is wrong. If you can't do t=
his,</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquo=
te type=3D"cite"><span>you are the one who should stop.</span><br></blockquo=
te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></=
span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ=
e=3D"cite"><span>Filtering out the unhelpful messages should be a lower prio=
rity than</span><br></blockquote></blockquote><blockquote type=3D"cite"><blo=
ckquote type=3D"cite"><span>soliciting more good ones that bring evidence an=
d logic to bear on a</span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span>narrow, specific question. This group=
 needs more messages of type 2, 3</span><br></blockquote></blockquote><block=
quote type=3D"cite"><blockquote type=3D"cite"><span>and 4 to make sure that e=
rrors do not persist. The persistence of</span><br></blockquote></blockquote=
><blockquote type=3D"cite"><blockquote type=3D"cite"><span>error is what und=
ermines consensus.</span><br></blockquote></blockquote><blockquote type=3D"c=
ite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><b=
lockquote type=3D"cite"><blockquote type=3D"cite"><span>You may not agree wi=
th what I propose here, but until the group can</span><br></blockquote></blo=
ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>articulate=
 a principled distinction between good messages and</span><br></blockquote><=
/blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>unhelp=
ful ones, it is dangerous to start down the path toward some</span><br></blo=
ckquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><sp=
an>vague notion of more stringent moderation, as many seemed inclined to</sp=
an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span>do:</span><br></blockquote></blockquote><blockquote type=3D"cit=
e"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><blo=
ckquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;Pol=
l: Should chairs be more draconian in doing moderation?</span><br></blockquo=
te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>y/=
n/no-opinion 65/2/7</span><br></blockquote></blockquote><blockquote type=3D"=
cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;https://notes.ietf.=
org/notes-ietf-126-tls</span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote>=
<blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp=
;(Versions: Thu, Jul 23, 2026 3:42 AM - Thu, Jul 23, 2026 7:27 PM.</span><br=
></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cit=
e"><span> &nbsp;&nbsp;&nbsp;The question was subsequently edited to read "mo=
derate more</span><br></blockquote></blockquote><blockquote type=3D"cite"><b=
lockquote type=3D"cite"><span>actively" in place of</span><br></blockquote><=
/blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp=
;&nbsp;&nbsp;"be more draconian." I imagine that the "draconian" version was=
</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t=
ype=3D"cite"><span>what people were</span><br></blockquote></blockquote><blo=
ckquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;res=
ponding to when they were polled.)</span><br></blockquote></blockquote><bloc=
kquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote=
></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>The m=
issing responses are the evidence for my claim that the current</span><br></=
blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite">=
<span>system of moderation is already encouraging people to self-censor.</sp=
an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite">=
<blockquote type=3D"cite"><span></span><br></blockquote></blockquote><blockq=
uote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote><=
/blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span># 4. C=
larifying the Red Herring</span><br></blockquote></blockquote><blockquote ty=
pe=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockq=
uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Here's the fi=
rst message that someone could have sent as a response to</span><br></blockq=
uote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>=
Ms. Connolly:</span><br></blockquote></blockquote><blockquote type=3D"cite">=
<blockquote type=3D"cite"><span></span><br></blockquote></blockquote><blockq=
uote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;Ms. Co=
nnolly's response to Mr. Jager is a red herring. The factor</span><br></bloc=
kquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><spa=
n>of 2 that she cites has no bearing on the assertion by Mr. Jager that</spa=
n><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span>she quotes.</span><br></blockquote></blockquote><blockquote typ=
e=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockqu=
ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&=
nbsp;To establish this, define some variables:</span><br></blockquote></bloc=
kquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br>=
</blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite=
"><span> &nbsp;&nbsp;&nbsp;xm =3D CPU seconds for the key-exchange computati=
ons required by</span><br></blockquote></blockquote><blockquote type=3D"cite=
"><blockquote type=3D"cite"><span>X25519MLKEM768.</span><br></blockquote></b=
lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><=
br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c=
ite"><span> &nbsp;&nbsp;&nbsp;m =3D CPU seconds for the key-exchange computa=
tions required by MLKEM768.</span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp=
;&nbsp;x =3D CPU seconds for the key-exchange computations required by X2551=
9.</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote=
 type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;Ms. Connolly notes=
 that r=3Dx/m=E2=89=882. The value that Mr. Jager refers</span><br></blockqu=
ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>t=
o as overhead is xm-m. As a rough approximation, xm will be equal to</span><=
br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c=
ite"><span>x+m so we can write</span><br></blockquote></blockquote><blockquo=
te type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></b=
lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;r =E2=89=88 (xm-m)/m.</span><=
br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c=
ite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite"><b=
lockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;For any given value of r, (=
xm-m) and m can vary together between</span><br></blockquote></blockquote><b=
lockquote type=3D"cite"><blockquote type=3D"cite"><span>zero and infinity.</=
span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ=
e=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"ci=
te"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;Less formally, for a g=
iven value r=E2=89=882, the extra time required to</span><br></blockquote></=
blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>do the X=
25519 key-exchange, x, might be huge--2 hours of CPU time--in</span><br></bl=
ockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><s=
pan>which case the time to do the MLKEM768 calculations will also be</span><=
br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c=
ite"><span>huge--1 hour of CPU time. In this case, running MLKEM768 instead o=
f</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t=
ype=3D"cite"><span>X25519MLKEM768 would save two hours of CPU time.</span><b=
r></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"ci=
te"><span></span><br></blockquote></blockquote><blockquote type=3D"cite"><bl=
ockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;&nbsp;Or, the time x require=
d for the X25519 calculations might be</span><br></blockquote></blockquote><=
blockquote type=3D"cite"><blockquote type=3D"cite"><span>tiny--2 nanoseconds=
--in which case the time for MLKEM768 would also be</span><br></blockquote><=
/blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>small-=
-1 nanosecond. In this case, using MLKEM768 instead of</span><br></blockquot=
e></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>X25=
519MLKEM768 would save a negligible 2 nanoseconds of CPU time.</span><br></b=
lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><=
span></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockqu=
ote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;The reference to r=3Dx/m=E2=89=88=
2 derails the discussion by getting the</span><br></blockquote></blockquote>=
<blockquote type=3D"cite"><blockquote type=3D"cite"><span>reader to stop pay=
ing attention to the relevant comparison (MLKEM768</span><br></blockquote></=
blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>versus X=
25519MLKEM768) and focus instead on an irrelevant comparison</span><br></blo=
ckquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><sp=
an>(X25519 versus MLKEM768).</span><br></blockquote></blockquote><blockquote=
 type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blo=
ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br=
></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cit=
e"><span></span><br></blockquote></blockquote><blockquote type=3D"cite"><blo=
ckquote type=3D"cite"><span># 5. Evidence That Supports Mr. Jager's Assertio=
n</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t=
ype=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"=
cite"><blockquote type=3D"cite"><span>Many people have asserted, as Mr. Jage=
r does, that the additional CPU</span><br></blockquote></blockquote><blockqu=
ote type=3D"cite"><blockquote type=3D"cite"><span>time required to run X2551=
9 during a TLS 1.3 handshake is negligible.</span><br></blockquote></blockqu=
ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>It might still=
 have been helpful to respond to the message from Ms.</span><br></blockquote=
></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Conn=
olly by taking other measurements from her source and using them</span><br><=
/blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"=
><span>to support Mr. Jager's assertion that the CPU time is negligible.</sp=
an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite">=
<blockquote type=3D"cite"><span>Here is a second message that does just that=
:</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t=
ype=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"=
cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;The table that Ms. C=
onnolly cited in her response to Mr. Jager</span><br></blockquote></blockquo=
te><blockquote type=3D"cite"><blockquote type=3D"cite"><span>includes measur=
ements that support his claim.</span><br></blockquote></blockquote><blockquo=
te type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;(https:/=
/blog.cloudflare.com/pq-2025/#ml-kem-versus-x25519)</span><br></blockquote><=
/blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span=
><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span> &nbsp;&nbsp;&nbsp;The table does not provide data on xm, but w=
e can estimate this</span><br></blockquote></blockquote><blockquote type=3D"=
cite"><blockquote type=3D"cite"><span>value using the approximation xm =E2=89=
=88 x + m. This holds because what</span><br></blockquote></blockquote><bloc=
kquote type=3D"cite"><blockquote type=3D"cite"><span>X25519MLKEM768 does is r=
un both the X25519 and the MLKEM768</span><br></blockquote></blockquote><blo=
ckquote type=3D"cite"><blockquote type=3D"cite"><span>key-exchange protocols=
. What Mr. Jager calls the overhead from</span><br></blockquote></blockquote=
><blockquote type=3D"cite"><blockquote type=3D"cite"><span>X25519MLKEM768 is=
 the extra CPU cycles required for X25519, which will</span><br></blockquote=
></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>be a=
pproximately equal to x.</span><br></blockquote></blockquote><blockquote typ=
e=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockqu=
ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&=
nbsp;If you invert the values from the Cloudflare table to get</span><br></b=
lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><=
span>measurements with units of CPU seconds per TLS connection, the key</spa=
n><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span>observation is</span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;Algorithm: X25519</span><br></blockquote></blockquote><bl=
ockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;Client seconds per op: 1/19000 =3D 5.3 * 10^(-5) seconds per TLS</=
span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ=
e=3D"cite"><span>1.3 connection</span><br></blockquote></blockquote><blockqu=
ote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;Server seconds per op: 1/19000 =3D 5.3 * 10^(-5) seconds per TLS</span>=
<br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"=
cite"><span>1.3 connection</span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp=
;&nbsp;The benefit from downgrading to MLKEM768 is the sum of the seconds</s=
pan><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=
=3D"cite"><span>saved on the client and the seconds saved on the server.</sp=
an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite">=
<blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;To convert this benefit i=
nto dollars, start with a conservative</span><br></blockquote></blockquote><=
blockquote type=3D"cite"><blockquote type=3D"cite"><span>estimate of the AWS=
 rental cost of a vCPU. The rate for a t4g.nano is</span><br></blockquote></=
blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>$0.0042=
 per hour of wall time but this permits only occasional bursts</span><br></b=
lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><=
span>of CPU. Unlimited mode costs $0.04 per vCPU hour for Graviton and</span=
><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span>$0.05 per vCPU hour for x86. A vCPU hour provides access to onl=
y one</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockqu=
ote type=3D"cite"><span>of the two hyper-threads that run on a physical core=
, so double the</span><br></blockquote></blockquote><blockquote type=3D"cite=
"><blockquote type=3D"cite"><span>x86 price to get $0.10 per hour as the hou=
rly rental rate for a core.</span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp=
;&nbsp;&nbsp;In dollars, the benefit B associated with x fewer CPU seconds i=
s</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t=
ype=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"=
cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;B =3D x * ($0.1 per hour) * (1/3600 hours per second)</span=
><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;=3D $2.9 * 10^(-9)</span><br></blockquote></blockquote><blockquote=
 type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blo=
ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nb=
sp;&nbsp;In an absolute sense, a benefit on the order of $10^(-9) is negligi=
ble.</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquo=
te type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=
=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;Any cost-benefi=
t calculation has both a cost and a benefit. To</span><br></blockquote></blo=
ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>assess the=
 benefit relative to the cost, we can use the concept of</span><br></blockqu=
ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>"=
willingness to pay" to get an estimate of the cost. Suppose that I</span><br=
></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cit=
e"><span>make 100 TLS 1.3 connections per day. (This is a "Feynman estimate"=
</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t=
ype=3D"cite"><span>that restricts the possibilities to powers of 10. I make m=
ore than 10</span><br></blockquote></blockquote><blockquote type=3D"cite"><b=
lockquote type=3D"cite"><span>connections per day and fewer than 1000, so th=
e answer I'll use is</span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span>100.)</span><br></blockquote></blockq=
uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></=
blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite">=
<span> &nbsp;&nbsp;&nbsp;&nbsp;I am willing to pay at least $10 to make sure=
 that for the next</span><br></blockquote></blockquote><blockquote type=3D"c=
ite"><blockquote type=3D"cite"><span>12 months, all my TLS 1.3 connections a=
re covered by X25519MLKEM768</span><br></blockquote></blockquote><blockquote=
 type=3D"cite"><blockquote type=3D"cite"><span>instead of MLKEM768. This imp=
lies that a lower bound on the cost I'd</span><br></blockquote></blockquote>=
<blockquote type=3D"cite"><blockquote type=3D"cite"><span>suffer from the re=
duction in security of a downgrade to MLKEM768 is</span><br></blockquote></b=
lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>$10 / (3=
65 * 100) =3D $2.7 * 10^(-4).</span><br></blockquote></blockquote><blockquot=
e type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></bl=
ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&n=
bsp;&nbsp;To summarize:</span><br></blockquote></blockquote><blockquote type=
=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;- Benefit from downgrading:</span><br></blockquote></blockquote><bl=
ockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;B =3D $2.9 * 10^(-=
9)</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote=
 type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;- Cost of downgrading:</span><br></blockquote></blockquote><blockquote=
 type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C =3D $2.7 * 10^(-4)</span=
><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite">=
<blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;Because the benefit is sm=
aller by five orders of magnitude, it is</span><br></blockquote></blockquote=
><blockquote type=3D"cite"><blockquote type=3D"cite"><span>negligible relati=
ve to the cost.</span><br></blockquote></blockquote><blockquote type=3D"cite=
"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><bloc=
kquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote=
></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></sp=
an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span># 6. Reaching Consensus</span><br></blockquote></blockquote><bl=
ockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquo=
te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>If=
 you disagree with my estimates, look for mistakes in my</span><br></blockqu=
ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>c=
alculations. If I made any, show the correct calculation. If I agree,</span>=
<br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"=
cite"><span>I'll say so.</span><br></blockquote></blockquote><blockquote typ=
e=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockqu=
ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Make your own a=
ssumptions. Get your own data. You don't have to use</span><br></blockquote>=
</blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>the v=
alues from the table provided by Cloudflare. Fire up OpenSSL 3.5</span><br><=
/blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"=
><span>and use it to get estimates for x, m, and xm on your hardware. Try</s=
pan><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=
=3D"cite"><span>measuring CPU usage using wall time or CPU time. (On macOS, u=
nless you</span><br></blockquote></blockquote><blockquote type=3D"cite"><blo=
ckquote type=3D"cite"><span>are running lots of other apps concurrently, I f=
ound that they are</span><br></blockquote></blockquote><blockquote type=3D"c=
ite"><blockquote type=3D"cite"><span>very similar.)</span><br></blockquote><=
/blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span=
><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span>Once several group members provide estimates, I'm willing to be=
t that</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockq=
uote type=3D"cite"><span>a consensus will emerge about the order of magnitud=
e of the two</span><br></blockquote></blockquote><blockquote type=3D"cite"><=
blockquote type=3D"cite"><span>critical values:</span><br></blockquote></blo=
ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nb=
sp;&nbsp;- B, the benefit from the downgrade to MLKEM768</span><br></blockqu=
ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &=
nbsp;&nbsp;&nbsp;- C, the cost in forgone security from the downgrade</span>=
<br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"=
cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite"><=
blockquote type=3D"cite"><span>When I say consensus, I mean agreement among p=
eople who have made a</span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span>credible attempt to estimate B and C.=
 Coming up with credible</span><br></blockquote></blockquote><blockquote typ=
e=3D"cite"><blockquote type=3D"cite"><span>estimates is an example of proof o=
f work. It is a good way to identify</span><br></blockquote></blockquote><bl=
ockquote type=3D"cite"><blockquote type=3D"cite"><span>the messages that mat=
ter. The others can safely be ignored.</span><br></blockquote></blockquote><=
blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockq=
uote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>=
The consensus to seek is like the consensus that the earth is a</span><br></=
blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite">=
<span>spheroid. You have to ignore the deniers who can generate an endless</=
span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ=
e=3D"cite"><span>word salad of inconsistencies, whataboutism, red herrings, a=
nd</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote=
 type=3D"cite"><span>negative-attention-getting-behavior.</span><br></blockq=
uote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>=
</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t=
ype=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"=
cite"><blockquote type=3D"cite"><span># 7. Next Steps</span><br></blockquote=
></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></sp=
an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span>Once there is a consensus on the size of B and C, it would be</=
span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ=
e=3D"cite"><span>revealing to consider these questions:</span><br></blockquo=
te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></=
span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ=
e=3D"cite"><span> &nbsp;&nbsp;&nbsp;7.1. Given how central Mr. Jager's asser=
tion about the magnitude</span><br></blockquote></blockquote><blockquote typ=
e=3D"cite"><blockquote type=3D"cite"><span>of B is to the choice between X25=
519MLKEM768 and MLKEM768, why didn't</span><br></blockquote></blockquote><bl=
ockquote type=3D"cite"><blockquote type=3D"cite"><span>anyone respond to the=
 red herring that prevented any consideration of</span><br></blockquote></bl=
ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>what he s=
aid?</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquo=
te type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=
=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;&nbsp;7.2. Does Ms. C=
onnolly now recognize that as a simple matter of</span><br></blockquote></bl=
ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>arithmeti=
c, the factor of 2 that she cited in her response to Mr.</span><br></blockqu=
ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>J=
ager tells us nothing about his assertion?</span><br></blockquote></blockquo=
te><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></bl=
ockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><s=
pan> &nbsp;&nbsp;&nbsp;7.3. Do all members of the TLS Working Group now agre=
e that Mr.</span><br></blockquote></blockquote><blockquote type=3D"cite"><bl=
ockquote type=3D"cite"><span>Jager's assertion is true? To wit, when someone=
 downgrades from the</span><br></blockquote></blockquote><blockquote type=3D=
"cite"><blockquote type=3D"cite"><span>protocol that the group recommends, X=
25519MLKEM768, to the new</span><br></blockquote></blockquote><blockquote ty=
pe=3D"cite"><blockquote type=3D"cite"><span>MLKEM768 alternative, the benefi=
t measured in CPU cycles saved is</span><br></blockquote></blockquote><block=
quote type=3D"cite"><blockquote type=3D"cite"><span>negligible both in an ab=
solute sense and relative to the cost of the</span><br></blockquote></blockq=
uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>forgone secur=
ity induced by the downgrade.</span><br></blockquote></blockquote><blockquot=
e type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></bl=
ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>The discu=
ssion of questions 7.1 and 7.2 will be of interest mainly to</span><br></blo=
ckquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><sp=
an>members of the group, but question 7.3 matters to people who have to</spa=
n><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span>make a decision about which PQ key-exchange protocol to adopt. A=
s</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t=
ype=3D"cite"><span>things stand, they now have reason to treat the TLS Worki=
ng Group as a</span><br></blockquote></blockquote><blockquote type=3D"cite">=
<blockquote type=3D"cite"><span>hesitant, unreliable advisor that for inexpl=
icably, refuses to answer</span><br></blockquote></blockquote><blockquote ty=
pe=3D"cite"><blockquote type=3D"cite"><span>question 7.3. A pivot to more ac=
tive moderation could further</span><br></blockquote></blockquote><blockquot=
e type=3D"cite"><blockquote type=3D"cite"><span>undermine their trust in the=
 group.</span><br></blockquote></blockquote><blockquote type=3D"cite"><block=
quote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span>The proven way to build trust i=
s to have an open discussion that</span><br></blockquote></blockquote><block=
quote type=3D"cite"><blockquote type=3D"cite"><span>addresses specific quest=
ions and converges to a clearly stated</span><br></blockquote></blockquote><=
blockquote type=3D"cite"><blockquote type=3D"cite"><span>consensus about the=
 answer. Question 7.3 might be a good place to</span><br></blockquote></bloc=
kquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>start.</spa=
n><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite">=
<blockquote type=3D"cite"><span></span><br></blockquote></blockquote><blockq=
uote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote><=
/blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span=
><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D=
"cite"><span># References</span><br></blockquote></blockquote><blockquote ty=
pe=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockq=
uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nbsp;&nbsp;=
&nbsp;- I have never been able to confirm whether Fermi made the</span><br><=
/blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"=
><span>statement I attribute to him in section 1.</span><br></blockquote></b=
lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><=
br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c=
ite"><span> &nbsp;&nbsp;&nbsp;- The characterization offered here of the dis=
cussions that</span><br></blockquote></blockquote><blockquote type=3D"cite">=
<blockquote type=3D"cite"><span>sustain science relies on _The Knowledge Mac=
hine_ by Michael Strevens.</span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block=
quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>____________=
___________________________________</span><br></blockquote></blockquote><blo=
ckquote type=3D"cite"><blockquote type=3D"cite"><span>TLS mailing list -- tl=
[email protected]</span><br></blockquote></blockquote><blockquote type=3D"cite"><bl=
ockquote type=3D"cite"><span>To unsubscribe send an email to tls-leave@ietf.=
org</span><br></blockquote></blockquote><blockquote type=3D"cite"><span></sp=
an><br></blockquote><blockquote type=3D"cite"><span></span><br></blockquote>=
<blockquote type=3D"cite"><span></span><br></blockquote><blockquote type=3D"=
cite"><span>--</span><br></blockquote><blockquote type=3D"cite"><span></span=
><br></blockquote><blockquote type=3D"cite"><span>Sophie Schmieg | Informati=
on Security Engineer | ISE Crypto | [email protected]</span><br></blockquo=
te><blockquote type=3D"cite"><span></span><br></blockquote><span></span><br>=
<span>_______________________________________________</span><br><span>TLS ma=
iling list -- [email protected]</span><br><span>To unsubscribe send an email to t=
[email protected]</span><br></div></blockquote></div></body></html>=

--Apple-Mail-BCB793CB-0196-4C4A-BE88-87910BB86FCD
Content-Type: image/png;
	name=wikipedia.png;
	x-apple-part-url=593C86C9-9902-4D00-A139-4C20B85AC11A
Content-Disposition: inline;
	filename=wikipedia.png
Content-Transfer-Encoding: base64
Content-Id: <593C86C9-9902-4D00-A139-4C20B85AC11A>

iVBORw0KGgoAAAANSUhEUgAAAKAAAACgCAAAAACupDjxAAAE6ElEQVR4AezOAQEAAAQAIP9PMwPU
giKHExQUFBQUFBQUFBQUFBS8GRQUFBQUFBQUFBQUFBQUFBQUFBQs4szAQ5UujMN/1I+RiLEkElki
RMRHCCEilhDiYkNEliyEi3AJIQsXi2VZliAkiwhZWWGM33dvzrzONHMWbjPzAJz7+R4z5zzvmfa/
m0KpWm92evejx+lkPOi1G7VSPmvndjzl7Wyx+mdp8DB9GPa7rUatXMzmPugUU3a+XG/3huPxsN9p
VPJ2qkIurfTNn3/fvR89jAbdZrVgp0r/LpiDgVceLYTxzC2ClMkHBLj9d8H3fjnEw64PvsinTj7w
f2wNj3Qf7yrQSdcGK/Jj2C5Aw6rcb66yB4/LW/jIzxwqNg1otNf0WLfgUZjLP3cXedEbHa93SJxp
GgIKB2rMND9quJ760KHGKqVe+ea6p/hFM3yjj6EsPPn/E5wZ008Xf8nvr52ZX/DIuPThlKBYUOeI
v7R4wVSdpKt3UPZUIA3PUPygzg4Asp8UtC3RjSDU25R3JB1e4O22mxM1fgfeuuyI9C4CQf6AYhlI
ERRzanQANEPKL4/62oIfXg8bND3CMgXuLcAKHtWDBVgfkQiyA8UmcMah+E1hIE8qcEY6jEbwDYo+
L6mqlSo99mkgc2CAW+nU9QVZ8UITmAFLKF70HTsiw058hVEJSgunvMD1hmHda0wKsI/hsZpHJniy
lUbRDdZN8c4zPQATBthZQNaJTJCDwGEQ9yygTY6tBeRODI3giNEJflOaCRRrkrwD8JMBnCxg7SMU
ZNNYms+MWrkjubaAgsMAC7UeneCzuTT3asX6MB+FmmzSqAR5ayzNzhL3FYCSywArKWV0glNjadhV
K6l9Iziw5WjPIxY8ZoylWUNRN8T4mJbGRCfIvrE0bELAs+Hpjxm14BrG0rxC+M+wf6195IKsG0vD
KjxeDQW4Y/SCSymNealu+mZ4j0HQyUtpjFeGvBM+hquMQZATc2lmwbu/MAKwiEXwkJLSGK8MJTds
DOecWAR5J6UxP91l2Bh+YDyC71Ia81Il5GMutY9JkFVjadqmUq/laz0OwbmpNGsI9eAYXsUmeLox
lKYFAW+XI7zG2AQ5DJRGdqC8/ublGF7EKLizQkvTAKxtQ7v7CyVpTDyCbIWV5u28K1+g6FB4kcbE
JSgWDf81Ir2nnHFrqx/u1CFWQZakND7poX5l6Om/I3UZr+BPKY2eYvuTpFuUu782hlcxC35lpDTa
de/Rf2W45xknJzfY+AT547I0VfktQa4MmYOM4WXsghv4S/MEYHZ5ZRh77z7vxC7Ihr80ZeDWufyV
wf5S82/C+AWffKVZ+l7jQH//fSB9SEDQLWilcUtAJWTS5JzzGO4yAUE+an8emV9csLpQzM5BWiUi
eEhLaZwiUA+9dxWdkjQmXkH9MU1/Bb4omzJOZHPGL7iSx1QA2sZfGaQxsQuyBsHamNcmTEpwAaFn
qpA0JglBJysSO/N9p8fEBDmCYvDNH1XWCQruVZDtAwM4Ofm8S06QbTkGxpA/JScoNcmeGMLRPjfG
TVSQZQD4+c3H6SOTFZydx5lhh6aA9GfCgif7my/ynjQmOUGOv7kKbO30JnFB7lwa+Tr+364dCwAA
AAAI87cOo2cRDCD/ICAgICAgICDgEyAgICAgICAgICAgICAgICBgYUeNfR+Kw20AAAAASUVORK5C
YII=

--Apple-Mail-BCB793CB-0196-4C4A-BE88-87910BB86FCD--

--Apple-Mail-5B35E89B-F2F0-4FA8-B937-116566B5BD8F--


--===============6564392036496953847==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp
bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0
bHMtbGVhdmVAaWV0Zi5vcmcK

--===============6564392036496953847==--