[TLS] Re: Improving the quality of the discussion on the TLS email list
[email protected] Thu, 30 Jul 2026 17:50:40 -0700
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <[email protected]> |
--===============6564392036496953847== Content-Type: multipart/alternative; boundary=Apple-Mail-5B35E89B-F2F0-4FA8-B937-116566B5BD8F Content-Transfer-Encoding: 7bit --Apple-Mail-5B35E89B-F2F0-4FA8-B937-116566B5BD8F Content-Type: multipart/related; type="text/html"; boundary=Apple-Mail-BCB793CB-0196-4C4A-BE88-87910BB86FCD Content-Transfer-Encoding: 7bit --Apple-Mail-BCB793CB-0196-4C4A-BE88-87910BB86FCD Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi= v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D= "auto">Hi Paul,<div><br></div><div>Both drafts have a =E2=80=9Crecommended t= o implement=E2=80=9D flag, where the hybrid draft is =E2=80=9CY=E2=80=9D and= the other draft is =E2=80=9CN=E2=80=9D. I believe the intention is for impl= ementers to look at these flags. It appears to me to be easier to understand= than several paragraphs of LLM output, but that=E2=80=99s just my perspecti= ve. </div><div><br></div><div>Your usage of =E2=80=9Cdowngrade=E2=80=9D= along the lines of Python versions is also confusing. There=E2=80=99s the o= bvious point (that Sophie referred to) that downgrade is a term of art in cr= yptography, eg has a very specific meaning in the field.</div><div><br></div= ><div>Ignoring that, your usage remains confusing. The natural point of comp= arison would have the hybrid scheme as the =E2=80=9Cearlier version=E2=80=9D= scheme. It is a transitional scheme while we gain confidence in MLKEM. If h= umanity is ever able to create a cryptographically relevant quantum computer= , it will have additional overhead for no benefit, and should be deprecated s= hortly thereafter.</div><div><br></div><div>Note that what you call a =E2=80= =9CFeynman estimate=E2=80=9D is not due to Feynman. Physicists instead call t= his technique a =E2=80=9CFermi Estimate=E2=80=9D, after Enrico Fermi. <= /div><div><br></div><div><div style=3D"display: block;" class=3D""><div styl= e=3D"-webkit-user-select: all; -webkit-user-drag: element; display: inline-b= lock;" class=3D"apple-rich-link" draggable=3D"true" role=3D"link" data-url=3D= "https://en.wikipedia.org/wiki/Fermi_problem"><a style=3D"border-radius:10px= ;font-family:-apple-system, Helvetica, Arial, sans-serif;display:block;-webk= it-user-select:none;width:300px;user-select:none;-webkit-user-modify:read-on= ly;user-modify:read-only;overflow:hidden;text-decoration:none;" class=3D"lp-= rich-link" rel=3D"nofollow" href=3D"https://en.wikipedia.org/wiki/Fermi_prob= lem" dir=3D"ltr" role=3D"button" draggable=3D"false" width=3D"300"><table st= yle=3D"table-layout:fixed;border-collapse:collapse;width:300px;background-co= lor:#E6E6E6;font-family:-apple-system, Helvetica, Arial, sans-serif;" class=3D= "lp-rich-link-emailBaseTable" cellpadding=3D"0" cellspacing=3D"0" border=3D"= 0" width=3D"300"><tbody><tr><td vertical-align=3D"center"><table bgcolor=3D"= #E6E6E6" cellpadding=3D"0" cellspacing=3D"0" width=3D"300" style=3D"table-la= yout:fixed;font-family:-apple-system, Helvetica, Arial, sans-serif;backgroun= d-color:rgba(230, 230, 230, 1);-apple-color-filter:initial;" class=3D"lp-ric= h-link-captionBar"><tbody><tr><td style=3D"padding:8px 0px 8px 0px;" class=3D= "lp-rich-link-captionBar-textStackItem"><div style=3D"max-width:100%;margin:= 0px 16px 0px 16px;overflow:hidden;" class=3D"lp-rich-link-captionBar-textSta= ck"><div style=3D"word-wrap:break-word;font-weight:500;font-size:12px;overfl= ow:hidden;text-overflow:ellipsis;text-align:left;" class=3D"lp-rich-link-cap= tionBar-textStack-topCaption-leading"><a rel=3D"nofollow" href=3D"https://en= .wikipedia.org/wiki/Fermi_problem" style=3D"text-decoration: none" draggable= =3D"false"><font color=3D"#000000" style=3D"color: rgba(0, 0, 0, 1);">Fermi p= roblem</font></a></div><div style=3D"word-wrap:break-word;font-weight:400;fo= nt-size:11px;overflow:hidden;text-overflow:ellipsis;text-align:left;" class=3D= "lp-rich-link-captionBar-textStack-bottomCaption-leading"><a rel=3D"nofollow= " href=3D"https://en.wikipedia.org/wiki/Fermi_problem" style=3D"text-decorat= ion: none" draggable=3D"false"><font color=3D"#A2A2A9" style=3D"color: rgba(= 60, 60, 67, 0.6);">en.wikipedia.org</font></a></div></div></td><td style=3D"= padding:6px 12px 6px 0px;" class=3D"lp-rich-link-captionBar-rightIconItem" w= idth=3D"30"><a rel=3D"nofollow" href=3D"https://en.wikipedia.org/wiki/Fermi_= problem" draggable=3D"false"><img style=3D"pointer-events:none !important;di= splay:inline-block;width:30px;height:30px;border-radius:3px;" width=3D"30" h= eight=3D"30" draggable=3D"false" class=3D"lp-rich-link-captionBar-rightIcon"= alt=3D"wikipedia.png" src=3D"cid:593C86C9-9902-4D00-A139-4C20B85AC11A"></a>= </td></tr></tbody></table></td></tr></tbody></table></a></div></div><br></di= v><div>This is a minor point. At the same time, it does not raise my confide= nce in the rest of the content of your messages. </div><div><br></div><= div>Best,</div><div><br></div><div>Mark</div><div><br id=3D"lineBreakAtBegin= ningOfSignature"><div dir=3D"ltr">Sent from my iPhone</div><div dir=3D"ltr">= <br><blockquote type=3D"cite">On Jul 30, 2026, at 2:31=E2=80=AFPM, Paul Rome= r <[email protected]> wrote:<br><br></blockquote></div>= <blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<span>Sophie (if I may):= </span><br><span></span><br><span>I have been puzzled by your emphasis on do= wngrade attacks. I never</span><br><span>mentioned them. I'll offer a conjec= ture below about why you emphasize</span><br><span>them.</span><br><span></s= pan><br><span>To focus on what I actually said, start with this sentence fro= m the</span><br><span>security considerations section of draft-ietf-tls-mlke= m-09.txt:</span><br><span></span><br><span> Implementers m= ust evaluate their specific security, performance, and</span><br><span> &nbs= p; operational constraints when deciding whether to deploy standa= lone</span><br><span> ML-KEM or a hybrid construction.</sp= an><br><span></span><br><span>The simplest claim that I make is that the TLS= Working Group should</span><br><span>try to give accurate, decision-relevan= t information to people who have</span><br><span>to choose what to deploy.</= span><br><span></span><br><span></span><br><span># Costs and Benefits</span>= <br><span>Let MLKEM768 and X25519MLKEM768 be the two protocols under</span><= br><span>consideration. The natural way to think about the choice between th= em</span><br><span>is to make one the baseline and assess the costs and bene= fits of a</span><br><span>switch to the other. All that matters for the deci= sion is the cost and</span><br><span>benefit of the change.</span><br><span>= </span><br><span>Take X25519MLKEM768 as the baseline. Consider the costs and= benefits</span><br><span>of a downgrade to MLKEM768 (where I am using the w= ord _downgrade_ in</span><br><span>the same way that someone speaks of a dow= ngrade from Python 3.13 to</span><br><span>3.12).</span><br><span></span><br= ><span>One of the benefits of the downgrade is that MLKEM768 does not need t= o</span><br><span>devote any CPU time to the elliptic curve calculations of X= 25519. Mr.</span><br><span>Jager claimed that this benefit was negligible. M= s. Connolly implied</span><br><span>that it not negligible because X25519 ta= kes twice as much CPU time as</span><br><span>MLKEM768.</span><br><span></sp= an><br><span>The simple point I made is that taking as given this factor of 2= , the</span><br><span>data cited by Ms. Connolly show that the cycle counts f= or both X25519</span><br><span>and MLKEM768 are so small that they are negli= gible.</span><br><span></span><br><span>I did not consider the reduction in t= he data that is exchanged because</span><br><span>neither Mr. Jager nor Ms. C= onnolly mentioned the cost of exchanging</span><br><span>data. Moreover, we k= now that the change in the data required is just</span><br><span>64 bytes.</= span><br><span></span><br><span>To emphasize that only a change in quantitie= s belongs in a</span><br><span>cost-benefit calculation, consider an upgrade= from MLKEM768 to</span><br><span>X25519MLKEM768. It does not matter how muc= h data is exchanged in the</span><br><span>base case (which now is MLKEM768.= ) Nor does it make sense to consider</span><br><span>the percentage increase= in the data exchanged because of the upgrade</span><br><span>to X25519MLKEM= 768. It isn't possible to attach a value to a percentage</span><br><span>or r= atio that lack units. It is possible to value on a reduction in</span><br><s= pan>the data that must be exchanged.</span><br><span></span><br><span>In the= same way, we can put a value on some quantity of CPU seconds.</span><br><sp= an>The data in the table that Ms. Connolly cites show that the downgrade</sp= an><br><span>to MLKEM768 will save roughly 1.1 * 10^(-4) CPU seconds per TLS= 1.3</span><br><span>connection. I converted this into dollars and compared i= t to an</span><br><span>estimate of the cost in dollars of the forgone secur= ity:</span><br><span></span><br><span>- Benefit from downgrading:</span><br>= <span> &nb= sp; B =3D $2.9 * 10^(-9) per TLS 1.3 connection</span><br><span><= /span><br><span>- Cost of downgrading:</span><br><span> &n= bsp; C =3D $2.7 * 10^(-= 4) per TLS 1.3 connection</span><br><span></span><br><span>I do not claim th= at my estimates of B and C are definitive. I</span><br><span>encouraged othe= rs to come up with alternative estimates.</span><br><span></span><br><span>W= hat I did claim was that if the discussion in this group focused on</span><b= r><span>specifics such as these, consensus would emerge naturally, just as i= t</span><br><span>does in science.</span><br><span></span><br><span>But now w= e have a puzzle. Why is this suggestion about doing a</span><br><span>cost-b= enefit analysis perceived as such a threat?</span><br><span></span><br><span= ></span><br><span># Why You Keep Referring to Downgrade Attacks</span><br><s= pan></span><br><span>Sophie, my conjecture is that you keep referring to the= impossibility</span><br><span>of downgrade attacks because you want to clai= m that no one is forced</span><br><span>to use MLKEM768. Let's stipulate tha= t. Everyone is free to choose.</span><br><span>Does this imply that making M= LKEM768 a standard will not do any harm?</span><br><span>No. If that argumen= t were correct, it would also apply to a standard</span><br><span>that calls= for no encryption of a TLS connection. Moreover, a large</span><br><span>li= terature on standards debunks the assertion that in a context where</span><b= r><span>many standards can emerge, free choice automatically supports an</sp= an><br><span>efficient outcome.</span><br><span></span><br><span>But set all= that aside. As a response to what I wrote, any defense of</span><br><span>t= he decision to bless MLKEM768 is off point. I was very explicit about</span>= <br><span>refraining from saying anything about whether or not it was good o= r</span><br><span>bad to formalize MLKEM768. I focused on the specific quest= ion I</span><br><span>highlighted above: Given that there are people who hav= e to decide what</span><br><span>to deploy, what can we offer to help them m= ake an informed decision?</span><br><span></span><br><span>Here we hit the p= uzzle again. Why is the suggestion that the group</span><br><span>provide in= formation about B and C perceived as a threat?</span><br><span></span><br><s= pan></span><br><span># The TLS Working Group Is in a Hole</span><br><span></= span><br><span>I think I understand why the message I submitted made people w= ho</span><br><span>supported publication of the RFC feel defensive and threa= tened. I</span><br><span>think everyone understands why.</span><br><span></s= pan><br><span>Hostility toward something as innocuous as a cost-benefit anal= ysis is</span><br><span>a sign of the damage that was done by the strategy o= f misdirection and</span><br><span>deception that was used to get the RFC pu= blished. If we accept that</span><br><span>the RFC would inevitably have bee= n published, it would be have been</span><br><span>better for the group to h= ave stated that it was publishing it because</span><br><span>government offi= cials want it and that interested parties should ask</span><br><span>them wh= y they wanted it.</span><br><span></span><br><span>The strategy that was use= d instead has leave the group in a hole. The</span><br><span>choice it can m= ake is to climb out or keep digging.</span><br><span></span><br><span>The wa= y to climb out is to copy the only social system that has ever</span><br><sp= an>delivered voluntary consensus, the system of science. The strategy of</sp= an><br><span>science may sometimes cause discomfort, but it is simple. Focus= </span><br><span>attention on specific bits of evidence that help resolve a p= recisely</span><br><span>formulated question. Make contributions public. Use= a proof of work to</span><br><span>filter out cheap talk.</span><br><span><= /span><br><span></span><br><span>On Tue, Jul 28, 2026 at 6:14=E2=80=AFPM Sop= hie Schmieg</span><br><span><[email protected]> w= rote:</span><br><blockquote type=3D"cite"><span></span><br></blockquote><blo= ckquote type=3D"cite"><span>It seems like the point you want to make, when c= ondensed to be more succinctly is that compute overhead of the handshake its= elf might be so small that a factor of three does not constitute a major ove= rhead. Indeed the cost of compute overhead tends to vary substantially betwe= en network architectures, with bandwidth usually far outweighing the cost of= compute. However, this is not the case for all networks, in particular conn= ections within a datacenter are usually compute constrained, not network lat= ency constrained. Deidre's point that there are situations where the hybrid h= as non-negligible overhead is therefore simply true, at least for some use c= ases.</span><br></blockquote><blockquote type=3D"cite"><span></span><br></bl= ockquote><blockquote type=3D"cite"><span>But more importantly, this question= is beside the point. Key exchange algorithms in TLS are negotiated in a dow= ngrade protected manner, and with current stacks preferring (usually exclusi= vely) hybrids over pure, the cost or lack thereof of a hybrid is not an obje= ction that should be seen as material to standardization to begin with. So t= he good news is that all your TLS connections will continue to use a hybrid,= without you having to pay a dime, with zero risk of a downgrade. You do not= even having to change your TLS configuration, as the hybrid is, as noted, d= efault in all relevant stacks. When using Chrome, you can check by hitting F1= 2 and looking at the security tab, where it should state which key exchange a= lgorithm was negotiated. Unless you deliberately change the defaults, and fi= nd a server which will offer pure ML-KEM, this will always read X25519MLKEM7= 68. Similar functionality exists in other browsers, too, and they too go wit= h X25519MLKEM768 unless specifically configured otherwise by yourself.</span= ><br></blockquote><blockquote type=3D"cite"><span></span><br></blockquote><b= lockquote type=3D"cite"><span>The algorithm choices are part of the key deri= vation function call, and so cannot be modified by an attacker without eithe= r forging a signature or having the participants notice and subsequently fai= l the handshake (an attacker with the power to modify traffic can always cau= se the handshake to fail, so this is not a DOS vector).</span><br></blockquo= te><blockquote type=3D"cite"><span></span><br></blockquote><blockquote type=3D= "cite"><span>As for conduct on the mailing list, my personal preference woul= d be the usage of smaller messages, especially when discussing overhead :). T= his means that when using an LLM to draft a message, it is usually more effi= cient to just send the prompt, instead of the usually fairly verbose output o= f the LLM.</span><br></blockquote><blockquote type=3D"cite"><span></span><br= ></blockquote><blockquote type=3D"cite"><span>On Tue, Jul 28, 2026 at 2:16=E2= =80=AFPM Paul Romer <[email protected]> wrote:</span><b= r></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></s= pan><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type= =3D"cite"><span>I started reading messages on the TLS list several weeks ago= after a</span><br></blockquote></blockquote><blockquote type=3D"cite"><bloc= kquote type=3D"cite"><span>blog post by Daniel Bernstein surfaced on Hacker N= ews calling</span><br></blockquote></blockquote><blockquote type=3D"cite"><b= lockquote type=3D"cite"><span>attention to the then-pending decision about w= hether to publish</span><br></blockquote></blockquote><blockquote type=3D"ci= te"><blockquote type=3D"cite"><span>"ML-KEM Post-Quantum Key Agreement for T= LS 1.3" as an RFC.</span><br></blockquote></blockquote><blockquote type=3D"c= ite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><b= lockquote type=3D"cite"><blockquote type=3D"cite"><span>On the basis of what= I read, I concluded that my status as a newcomer</span><br></blockquote></b= lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>would di= squalify me from participating in that decision. I withheld my</span><br></b= lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><= span>comments until the decision was made.</span><br></blockquote></blockquo= te><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></bl= ockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><s= pan>I share the concern that many members voice: the group discussion is</sp= an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span>dysfunctional. I'm writing now because I fear that suggestions a= bout</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquo= te type=3D"cite"><span>how to do better are not informed by an accurate diag= nosis of the</span><br></blockquote></blockquote><blockquote type=3D"cite"><= blockquote type=3D"cite"><span>problem and that the measures being considere= d will make the</span><br></blockquote></blockquote><blockquote type=3D"cite= "><blockquote type=3D"cite"><span>underlying problem worse.</span><br></bloc= kquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><spa= n></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote= type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote>= <blockquote type=3D"cite"><blockquote type=3D"cite"><span># 1. Science as th= e Model for How To Reach a Consensus</span><br></blockquote></blockquote><bl= ockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquo= te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Th= e oral tradition I absorbed as an undergraduate included a</span><br></block= quote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span= >description of science that was attributed to Enrico Fermi: "Science</span>= <br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"= cite"><span>is a process for reaching consensus." At the time, I vigorously<= /span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote ty= pe=3D"cite"><span>disagreed. This description seemed to open the door to all= kinds of</span><br></blockquote></blockquote><blockquote type=3D"cite"><blo= ckquote type=3D"cite"><span>unscientific ways to reach a consensus. But over= time, I've come to</span><br></blockquote></blockquote><blockquote type=3D"= cite"><blockquote type=3D"cite"><span>appreciate it, provided we make explic= it the assumption that consensus</span><br></blockquote></blockquote><blockq= uote type=3D"cite"><blockquote type=3D"cite"><span>is voluntary. I'd rephras= e it as:</span><br></blockquote></blockquote><blockquote type=3D"cite"><bloc= kquote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span> **Science is= the only social system that has ever achieved broad</span><br></blockquote>= </blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>conse= nsus without coercion.**</span><br></blockquote></blockquote><blockquote typ= e=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockqu= ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Billions of pe= ople share a consensus that the earth is a spheroid, not</span><br></blockqu= ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>a= flat disk. To be sure, there are deniers. There are always deniers.</span><= br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c= ite"><span>But the consensus among billions is astonishing.</span><br></bloc= kquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><spa= n></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote= type=3D"cite"><span>My diagnosis of the problems with the TLS Working Group= draws on my</span><br></blockquote></blockquote><blockquote type=3D"cite"><= blockquote type=3D"cite"><span>understanding of how scientists reach consens= us.</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquot= e type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span>A. Participants agree on two principl= es:</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquot= e type=3D"cite"><span> - Evidence is the ultimate arbiter o= f truth.</span><br></blockquote></blockquote><blockquote type=3D"cite"><bloc= kquote type=3D"cite"><span> - There are objective rules fo= r logical inference.</span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote>= <blockquote type=3D"cite"><blockquote type=3D"cite"><span>B. In their discou= rse, scientists exchange several types of "good" messages:</span><br></block= quote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span= > 1. Good messages almost always focus on specifics that a= llow a</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockq= uote type=3D"cite"><span>direct connection to evidence.</span><br></blockquo= te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &= nbsp; 2. Some good messages contribute new evidence and use logic= to</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquot= e type=3D"cite"><span>summarize the implications of the augmented body of ev= idence.</span><br></blockquote></blockquote><blockquote type=3D"cite"><block= quote type=3D"cite"><span> 3. Other good messages challeng= e misstatements about the evidence</span><br></blockquote></blockquote><bloc= kquote type=3D"cite"><blockquote type=3D"cite"><span>cited by others.</span>= <br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"= cite"><span> 4. Still other good messages uncover flaws in= the logic used to</span><br></blockquote></blockquote><blockquote type=3D"c= ite"><blockquote type=3D"cite"><span>draw implications from the available ev= idence.</span><br></blockquote></blockquote><blockquote type=3D"cite"><block= quote type=3D"cite"><span> 5. When someone contributes a m= essage that is subsequently shown</span><br></blockquote></blockquote><block= quote type=3D"cite"><blockquote type=3D"cite"><span>to be false or misleadin= g, this contributor sends a particularly</span><br></blockquote></blockquote= ><blockquote type=3D"cite"><blockquote type=3D"cite"><span>important type of= follow-up message that acknowledges the flaws in the</span><br></blockquote= ></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>cont= ributor's message and recognizes the accuracy of the analysis by</span><br><= /blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"= ><span>others.</span><br></blockquote></blockquote><blockquote type=3D"cite"= ><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><block= quote type=3D"cite"><blockquote type=3D"cite"><span>The striking thing about= this list is that although it has many</span><br></blockquote></blockquote>= <blockquote type=3D"cite"><blockquote type=3D"cite"><span>talented members, i= t receives few good messages. In what follows, I'll</span><br></blockquote><= /blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>give s= pecific examples, of missing messages: a message of type 2 and a</span><br><= /blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"= ><span>message of type 4 that no one sent even though there surely were</spa= n><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span>members who understood the points that these two messages conve= y.</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote= type=3D"cite"><span>Because no one responded, an error persisted.</span><br= ></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cit= e"><span></span><br></blockquote></blockquote><blockquote type=3D"cite"><blo= ckquote type=3D"cite"><span>More moderation will not get you the messages th= at this list needs.</span><br></blockquote></blockquote><blockquote type=3D"= cite"><blockquote type=3D"cite"><span>The missing messages suggest that a co= ncern about what is permitted</span><br></blockquote></blockquote><blockquot= e type=3D"cite"><blockquote type=3D"cite"><span>may already be encouraging p= eople to self-censor. There are too many</span><br></blockquote></blockquote= ><blockquote type=3D"cite"><blockquote type=3D"cite"><span>messages that con= tribute noise, but there are safer ways to limit the</span><br></blockquote>= </blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>harm t= hey do.</span><br></blockquote></blockquote><blockquote type=3D"cite"><block= quote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br><= /blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"= ><span># 2. Specifics</span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote>= <blockquote type=3D"cite"><blockquote type=3D"cite"><span>Participants in sc= ientific discussions focus doggedly on narrow</span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>assertions a= bout specifics. This is how the community sustains its</span><br></blockquot= e></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>com= mitment to the principle that evidence is the ultimate arbiter of</span><br>= </blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite= "><span>truth.</span><br></blockquote></blockquote><blockquote type=3D"cite"= ><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><block= quote type=3D"cite"><blockquote type=3D"cite"><span>In that spirit, I will f= ocus on a specific email exchange from</span><br></blockquote></blockquote><= blockquote type=3D"cite"><blockquote type=3D"cite"><span>February 2026 that c= onsists of an assertion and a response. Both are</span><br></blockquote></bl= ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>specific e= nough that one can assess whether they are accurate and on</span><br></block= quote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span= >point.</span><br></blockquote></blockquote><blockquote type=3D"cite"><block= quote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span>On 27 February 2026, Tibor Jage= r wrote:</span><br></blockquote></blockquote><blockquote type=3D"cite"><bloc= kquote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span> "the use of h= ybrid crypto comes with negligible overhead,</span><br></blockquote></blockq= uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> = as for ML-KEM + ECC."</span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>https://mail= archive.ietf.org/arch/msg/tls/4PcWkID3bs4M_-He_OL0jy5CyZY/</span><br></block= quote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span= ></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t= ype=3D"cite"><span>That same day, Deirdre Connolly replied:</span><br></bloc= kquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><spa= n></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote= type=3D"cite"><span> "X25519 is almost twice as slow as M= LKEM768 (</span><br></blockquote></blockquote><blockquote type=3D"cite"><blo= ckquote type=3D"cite"><span> https://blog.cloudflare.com/p= q-2025/#ml-kem-versus-x25519)"</span><br></blockquote></blockquote><blockquo= te type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></b= lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>https://= mailarchive.ietf.org/arch/msg/tls/dSP0hWuwt_zVuMhZmGpMmftPJS4/</span><br></b= lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><= span></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockqu= ote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote typ= e=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockqu= ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span># 3. Red Herri= ngs and Intent</span><br></blockquote></blockquote><blockquote type=3D"cite"= ><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><block= quote type=3D"cite"><blockquote type=3D"cite"><span>According to Wikipedia, a= red herring misleads or distracts from a</span><br></blockquote></blockquot= e><blockquote type=3D"cite"><blockquote type=3D"cite"><span>relevant or impo= rtant question. Someone can inject a red herring</span><br></blockquote></bl= ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>intention= ally or inadvertently.</span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote>= <blockquote type=3D"cite"><blockquote type=3D"cite"><span>Section 4 gives an= example of a message of type 4 that finds fault</span><br></blockquote></bl= ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>with the l= ogic of the response by Ms. Connolly. It shows that her</span><br></blockquo= te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>re= sponse is a red herring. A simple arithmetic argument shows that the</span><= br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c= ite"><span>factor of 2 that she cites has zero bearing on the assertion by M= r.</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote= type=3D"cite"><span>Jager.</span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Section 5 ha= s a message of type 2 that adds new evidence, in this</span><br></blockquote= ></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>case= , evidence drawn from the source that Ms. Connolly cites. This new</span><br= ></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cit= e"><span>evidence supports Mr. Jager's assertion.</span><br></blockquote></b= lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><= br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c= ite"><span>Under the norms of science, the appropriate response to a red her= ring</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquo= te type=3D"cite"><span>is to show how it misleads and correct it. This does n= ot require any</span><br></blockquote></blockquote><blockquote type=3D"cite"= ><blockquote type=3D"cite"><span>discussion about the intent of the person w= ho contributed it. In fact,</span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span>it would be a huge mistake to r= espond by launching an inquisition into</span><br></blockquote></blockquote>= <blockquote type=3D"cite"><blockquote type=3D"cite"><span>intent. The red he= rring has already derailed the work of the group. An</span><br></blockquote>= </blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>inqui= ry into intent compounds the damage by wasting time and energy</span><br></b= lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><= span>that should be devoted to the work of the group, agreeing on specific</= span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ= e=3D"cite"><span>assertions that are true.</span><br></blockquote></blockquo= te><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></bl= ockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><s= pan>One clear sign of the dysfunction in this group is the many emails</span= ><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span>devoted to a discussion of intent. It is easy to understand the= appeal</span><br></blockquote></blockquote><blockquote type=3D"cite"><block= quote type=3D"cite"><span>of a system of moderation that could filter them o= ut, but there are</span><br></blockquote></blockquote><blockquote type=3D"ci= te"><blockquote type=3D"cite"><span>other possible responses, including the l= ighter touch of social</span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span>pressure that discourages contributio= ns that are off point. In section</span><br></blockquote></blockquote><block= quote type=3D"cite"><blockquote type=3D"cite"><span>6, "Reaching Consensus",= I suggest another way to filter out cheap</span><br></blockquote></blockquo= te><blockquote type=3D"cite"><blockquote type=3D"cite"><span>talk: require t= he author to use evidence and logic to reach a</span><br></blockquote></bloc= kquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>conclusion a= nd ignore any messages that do not live up to this</span><br></blockquote></= blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>standar= d. This is an instance of what has come to be known as proof of</span><br></= blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite">= <span>work.</span><br></blockquote></blockquote><blockquote type=3D"cite"><b= lockquote type=3D"cite"><span></span><br></blockquote></blockquote><blockquo= te type=3D"cite"><blockquote type=3D"cite"><span>One advantage of this parti= cular type of proof of work is that it</span><br></blockquote></blockquote><= blockquote type=3D"cite"><blockquote type=3D"cite"><span>respects the sharp d= istinction that must be drawn between a good</span><br></blockquote></blockq= uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>message that s= ays "these facts and logic show that your assertion is</span><br></blockquot= e></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>wro= ng" and a bad message that says "many of us don't like what you are</span><b= r></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"ci= te"><span>saying so please stop saying it."</span><br></blockquote></blockqu= ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></b= lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><= span>The way to get someone to stop making an assertion is to marshal</span>= <br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"= cite"><span>evidence and logic which show that it is wrong. If you can't do t= his,</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquo= te type=3D"cite"><span>you are the one who should stop.</span><br></blockquo= te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></= span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ= e=3D"cite"><span>Filtering out the unhelpful messages should be a lower prio= rity than</span><br></blockquote></blockquote><blockquote type=3D"cite"><blo= ckquote type=3D"cite"><span>soliciting more good ones that bring evidence an= d logic to bear on a</span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span>narrow, specific question. This group= needs more messages of type 2, 3</span><br></blockquote></blockquote><block= quote type=3D"cite"><blockquote type=3D"cite"><span>and 4 to make sure that e= rrors do not persist. The persistence of</span><br></blockquote></blockquote= ><blockquote type=3D"cite"><blockquote type=3D"cite"><span>error is what und= ermines consensus.</span><br></blockquote></blockquote><blockquote type=3D"c= ite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><b= lockquote type=3D"cite"><blockquote type=3D"cite"><span>You may not agree wi= th what I propose here, but until the group can</span><br></blockquote></blo= ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>articulate= a principled distinction between good messages and</span><br></blockquote><= /blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>unhelp= ful ones, it is dangerous to start down the path toward some</span><br></blo= ckquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><sp= an>vague notion of more stringent moderation, as many seemed inclined to</sp= an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span>do:</span><br></blockquote></blockquote><blockquote type=3D"cit= e"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><blo= ckquote type=3D"cite"><blockquote type=3D"cite"><span> Pol= l: Should chairs be more draconian in doing moderation?</span><br></blockquo= te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>y/= n/no-opinion 65/2/7</span><br></blockquote></blockquote><blockquote type=3D"= cite"><blockquote type=3D"cite"><span> https://notes.ietf.= org/notes-ietf-126-tls</span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockquote>= <blockquote type=3D"cite"><blockquote type=3D"cite"><span>  = ;(Versions: Thu, Jul 23, 2026 3:42 AM - Thu, Jul 23, 2026 7:27 PM.</span><br= ></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cit= e"><span> The question was subsequently edited to read "mo= derate more</span><br></blockquote></blockquote><blockquote type=3D"cite"><b= lockquote type=3D"cite"><span>actively" in place of</span><br></blockquote><= /blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>  = ; "be more draconian." I imagine that the "draconian" version was= </span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t= ype=3D"cite"><span>what people were</span><br></blockquote></blockquote><blo= ckquote type=3D"cite"><blockquote type=3D"cite"><span> res= ponding to when they were polled.)</span><br></blockquote></blockquote><bloc= kquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote= ></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>The m= issing responses are the evidence for my claim that the current</span><br></= blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite">= <span>system of moderation is already encouraging people to self-censor.</sp= an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite">= <blockquote type=3D"cite"><span></span><br></blockquote></blockquote><blockq= uote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote><= /blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span># 4. C= larifying the Red Herring</span><br></blockquote></blockquote><blockquote ty= pe=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockq= uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Here's the fi= rst message that someone could have sent as a response to</span><br></blockq= uote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>= Ms. Connolly:</span><br></blockquote></blockquote><blockquote type=3D"cite">= <blockquote type=3D"cite"><span></span><br></blockquote></blockquote><blockq= uote type=3D"cite"><blockquote type=3D"cite"><span> Ms. Co= nnolly's response to Mr. Jager is a red herring. The factor</span><br></bloc= kquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><spa= n>of 2 that she cites has no bearing on the assertion by Mr. Jager that</spa= n><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span>she quotes.</span><br></blockquote></blockquote><blockquote typ= e=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockqu= ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &= nbsp;To establish this, define some variables:</span><br></blockquote></bloc= kquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br>= </blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite= "><span> xm =3D CPU seconds for the key-exchange computati= ons required by</span><br></blockquote></blockquote><blockquote type=3D"cite= "><blockquote type=3D"cite"><span>X25519MLKEM768.</span><br></blockquote></b= lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><= br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c= ite"><span> m =3D CPU seconds for the key-exchange computa= tions required by MLKEM768.</span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>  = ; x =3D CPU seconds for the key-exchange computations required by X2551= 9.</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote= type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span> Ms. Connolly notes= that r=3Dx/m=E2=89=882. The value that Mr. Jager refers</span><br></blockqu= ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>t= o as overhead is xm-m. As a rough approximation, xm will be equal to</span><= br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c= ite"><span>x+m so we can write</span><br></blockquote></blockquote><blockquo= te type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></b= lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &= nbsp; r =E2=89=88 (xm-m)/m.</span><= br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c= ite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite"><b= lockquote type=3D"cite"><span> For any given value of r, (= xm-m) and m can vary together between</span><br></blockquote></blockquote><b= lockquote type=3D"cite"><blockquote type=3D"cite"><span>zero and infinity.</= span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ= e=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"ci= te"><blockquote type=3D"cite"><span> Less formally, for a g= iven value r=E2=89=882, the extra time required to</span><br></blockquote></= blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>do the X= 25519 key-exchange, x, might be huge--2 hours of CPU time--in</span><br></bl= ockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><s= pan>which case the time to do the MLKEM768 calculations will also be</span><= br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c= ite"><span>huge--1 hour of CPU time. In this case, running MLKEM768 instead o= f</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t= ype=3D"cite"><span>X25519MLKEM768 would save two hours of CPU time.</span><b= r></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"ci= te"><span></span><br></blockquote></blockquote><blockquote type=3D"cite"><bl= ockquote type=3D"cite"><span> Or, the time x require= d for the X25519 calculations might be</span><br></blockquote></blockquote><= blockquote type=3D"cite"><blockquote type=3D"cite"><span>tiny--2 nanoseconds= --in which case the time for MLKEM768 would also be</span><br></blockquote><= /blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>small-= -1 nanosecond. In this case, using MLKEM768 instead of</span><br></blockquot= e></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>X25= 519MLKEM768 would save a negligible 2 nanoseconds of CPU time.</span><br></b= lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><= span></span><br></blockquote></blockquote><blockquote type=3D"cite"><blockqu= ote type=3D"cite"><span> The reference to r=3Dx/m=E2=89=88= 2 derails the discussion by getting the</span><br></blockquote></blockquote>= <blockquote type=3D"cite"><blockquote type=3D"cite"><span>reader to stop pay= ing attention to the relevant comparison (MLKEM768</span><br></blockquote></= blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>versus X= 25519MLKEM768) and focus instead on an irrelevant comparison</span><br></blo= ckquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><sp= an>(X25519 versus MLKEM768).</span><br></blockquote></blockquote><blockquote= type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blo= ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br= ></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cit= e"><span></span><br></blockquote></blockquote><blockquote type=3D"cite"><blo= ckquote type=3D"cite"><span># 5. Evidence That Supports Mr. Jager's Assertio= n</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t= ype=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"= cite"><blockquote type=3D"cite"><span>Many people have asserted, as Mr. Jage= r does, that the additional CPU</span><br></blockquote></blockquote><blockqu= ote type=3D"cite"><blockquote type=3D"cite"><span>time required to run X2551= 9 during a TLS 1.3 handshake is negligible.</span><br></blockquote></blockqu= ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>It might still= have been helpful to respond to the message from Ms.</span><br></blockquote= ></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Conn= olly by taking other measurements from her source and using them</span><br><= /blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"= ><span>to support Mr. Jager's assertion that the CPU time is negligible.</sp= an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite">= <blockquote type=3D"cite"><span>Here is a second message that does just that= :</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t= ype=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"= cite"><blockquote type=3D"cite"><span> The table that Ms. C= onnolly cited in her response to Mr. Jager</span><br></blockquote></blockquo= te><blockquote type=3D"cite"><blockquote type=3D"cite"><span>includes measur= ements that support his claim.</span><br></blockquote></blockquote><blockquo= te type=3D"cite"><blockquote type=3D"cite"><span> (https:/= /blog.cloudflare.com/pq-2025/#ml-kem-versus-x25519)</span><br></blockquote><= /blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span= ><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span> The table does not provide data on xm, but w= e can estimate this</span><br></blockquote></blockquote><blockquote type=3D"= cite"><blockquote type=3D"cite"><span>value using the approximation xm =E2=89= =88 x + m. This holds because what</span><br></blockquote></blockquote><bloc= kquote type=3D"cite"><blockquote type=3D"cite"><span>X25519MLKEM768 does is r= un both the X25519 and the MLKEM768</span><br></blockquote></blockquote><blo= ckquote type=3D"cite"><blockquote type=3D"cite"><span>key-exchange protocols= . What Mr. Jager calls the overhead from</span><br></blockquote></blockquote= ><blockquote type=3D"cite"><blockquote type=3D"cite"><span>X25519MLKEM768 is= the extra CPU cycles required for X25519, which will</span><br></blockquote= ></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>be a= pproximately equal to x.</span><br></blockquote></blockquote><blockquote typ= e=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockqu= ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &= nbsp;If you invert the values from the Cloudflare table to get</span><br></b= lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><= span>measurements with units of CPU seconds per TLS connection, the key</spa= n><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span>observation is</span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>  = ; Algorithm: X25519</span><br></blockquote></blockquote><bl= ockquote type=3D"cite"><blockquote type=3D"cite"><span> &n= bsp; Client seconds per op: 1/19000 =3D 5.3 * 10^(-5) seconds per TLS</= span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ= e=3D"cite"><span>1.3 connection</span><br></blockquote></blockquote><blockqu= ote type=3D"cite"><blockquote type=3D"cite"><span> &= nbsp;Server seconds per op: 1/19000 =3D 5.3 * 10^(-5) seconds per TLS</span>= <br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"= cite"><span>1.3 connection</span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>  = ; The benefit from downgrading to MLKEM768 is the sum of the seconds</s= pan><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type= =3D"cite"><span>saved on the client and the seconds saved on the server.</sp= an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite">= <blockquote type=3D"cite"><span> To convert this benefit i= nto dollars, start with a conservative</span><br></blockquote></blockquote><= blockquote type=3D"cite"><blockquote type=3D"cite"><span>estimate of the AWS= rental cost of a vCPU. The rate for a t4g.nano is</span><br></blockquote></= blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>$0.0042= per hour of wall time but this permits only occasional bursts</span><br></b= lockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><= span>of CPU. Unlimited mode costs $0.04 per vCPU hour for Graviton and</span= ><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span>$0.05 per vCPU hour for x86. A vCPU hour provides access to onl= y one</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockqu= ote type=3D"cite"><span>of the two hyper-threads that run on a physical core= , so double the</span><br></blockquote></blockquote><blockquote type=3D"cite= "><blockquote type=3D"cite"><span>x86 price to get $0.10 per hour as the hou= rly rental rate for a core.</span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>  = ; In dollars, the benefit B associated with x fewer CPU seconds i= s</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t= ype=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"= cite"><blockquote type=3D"cite"><span> &= nbsp; B =3D x * ($0.1 per hour) * (1/3600 hours per second)</span= ><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span> &n= bsp; =3D $2.9 * 10^(-9)</span><br></blockquote></blockquote><blockquote= type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blo= ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nb= sp; In an absolute sense, a benefit on the order of $10^(-9) is negligi= ble.</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquo= te type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type= =3D"cite"><blockquote type=3D"cite"><span> Any cost-benefi= t calculation has both a cost and a benefit. To</span><br></blockquote></blo= ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>assess the= benefit relative to the cost, we can use the concept of</span><br></blockqu= ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>"= willingness to pay" to get an estimate of the cost. Suppose that I</span><br= ></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cit= e"><span>make 100 TLS 1.3 connections per day. (This is a "Feynman estimate"= </span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t= ype=3D"cite"><span>that restricts the possibilities to powers of 10. I make m= ore than 10</span><br></blockquote></blockquote><blockquote type=3D"cite"><b= lockquote type=3D"cite"><span>connections per day and fewer than 1000, so th= e answer I'll use is</span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span>100.)</span><br></blockquote></blockq= uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></= blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite">= <span> I am willing to pay at least $10 to make sure= that for the next</span><br></blockquote></blockquote><blockquote type=3D"c= ite"><blockquote type=3D"cite"><span>12 months, all my TLS 1.3 connections a= re covered by X25519MLKEM768</span><br></blockquote></blockquote><blockquote= type=3D"cite"><blockquote type=3D"cite"><span>instead of MLKEM768. This imp= lies that a lower bound on the cost I'd</span><br></blockquote></blockquote>= <blockquote type=3D"cite"><blockquote type=3D"cite"><span>suffer from the re= duction in security of a downgrade to MLKEM768 is</span><br></blockquote></b= lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>$10 / (3= 65 * 100) =3D $2.7 * 10^(-4).</span><br></blockquote></blockquote><blockquot= e type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></bl= ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &n= bsp; To summarize:</span><br></blockquote></blockquote><blockquote type= =3D"cite"><blockquote type=3D"cite"><span> &nb= sp; - Benefit from downgrading:</span><br></blockquote></blockquote><bl= ockquote type=3D"cite"><blockquote type=3D"cite"><span> &n= bsp; B =3D $2.9 * 10^(-= 9)</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote= type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span> = - Cost of downgrading:</span><br></blockquote></blockquote><blockquote= type=3D"cite"><blockquote type=3D"cite"><span> &nbs= p; C =3D $2.7 * 10^(-4)</span= ><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite">= <blockquote type=3D"cite"><span> Because the benefit is sm= aller by five orders of magnitude, it is</span><br></blockquote></blockquote= ><blockquote type=3D"cite"><blockquote type=3D"cite"><span>negligible relati= ve to the cost.</span><br></blockquote></blockquote><blockquote type=3D"cite= "><blockquote type=3D"cite"><span></span><br></blockquote></blockquote><bloc= kquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote= ></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></sp= an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span># 6. Reaching Consensus</span><br></blockquote></blockquote><bl= ockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquo= te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>If= you disagree with my estimates, look for mistakes in my</span><br></blockqu= ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>c= alculations. If I made any, show the correct calculation. If I agree,</span>= <br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"= cite"><span>I'll say so.</span><br></blockquote></blockquote><blockquote typ= e=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockqu= ote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>Make your own a= ssumptions. Get your own data. You don't have to use</span><br></blockquote>= </blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>the v= alues from the table provided by Cloudflare. Fire up OpenSSL 3.5</span><br><= /blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"= ><span>and use it to get estimates for x, m, and xm on your hardware. Try</s= pan><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type= =3D"cite"><span>measuring CPU usage using wall time or CPU time. (On macOS, u= nless you</span><br></blockquote></blockquote><blockquote type=3D"cite"><blo= ckquote type=3D"cite"><span>are running lots of other apps concurrently, I f= ound that they are</span><br></blockquote></blockquote><blockquote type=3D"c= ite"><blockquote type=3D"cite"><span>very similar.)</span><br></blockquote><= /blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span= ><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span>Once several group members provide estimates, I'm willing to be= t that</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockq= uote type=3D"cite"><span>a consensus will emerge about the order of magnitud= e of the two</span><br></blockquote></blockquote><blockquote type=3D"cite"><= blockquote type=3D"cite"><span>critical values:</span><br></blockquote></blo= ckquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &nb= sp; - B, the benefit from the downgrade to MLKEM768</span><br></blockqu= ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> &= nbsp; - C, the cost in forgone security from the downgrade</span>= <br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"= cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite"><= blockquote type=3D"cite"><span>When I say consensus, I mean agreement among p= eople who have made a</span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span>credible attempt to estimate B and C.= Coming up with credible</span><br></blockquote></blockquote><blockquote typ= e=3D"cite"><blockquote type=3D"cite"><span>estimates is an example of proof o= f work. It is a good way to identify</span><br></blockquote></blockquote><bl= ockquote type=3D"cite"><blockquote type=3D"cite"><span>the messages that mat= ter. The others can safely be ignored.</span><br></blockquote></blockquote><= blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockq= uote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>= The consensus to seek is like the consensus that the earth is a</span><br></= blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite">= <span>spheroid. You have to ignore the deniers who can generate an endless</= span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ= e=3D"cite"><span>word salad of inconsistencies, whataboutism, red herrings, a= nd</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote= type=3D"cite"><span>negative-attention-getting-behavior.</span><br></blockq= uote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>= </span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t= ype=3D"cite"><span></span><br></blockquote></blockquote><blockquote type=3D"= cite"><blockquote type=3D"cite"><span># 7. Next Steps</span><br></blockquote= ></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></sp= an><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span>Once there is a consensus on the size of B and C, it would be</= span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ= e=3D"cite"><span>revealing to consider these questions:</span><br></blockquo= te></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></= span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote typ= e=3D"cite"><span> 7.1. Given how central Mr. Jager's asser= tion about the magnitude</span><br></blockquote></blockquote><blockquote typ= e=3D"cite"><blockquote type=3D"cite"><span>of B is to the choice between X25= 519MLKEM768 and MLKEM768, why didn't</span><br></blockquote></blockquote><bl= ockquote type=3D"cite"><blockquote type=3D"cite"><span>anyone respond to the= red herring that prevented any consideration of</span><br></blockquote></bl= ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>what he s= aid?</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquo= te type=3D"cite"><span></span><br></blockquote></blockquote><blockquote type= =3D"cite"><blockquote type=3D"cite"><span> 7.2. Does Ms. C= onnolly now recognize that as a simple matter of</span><br></blockquote></bl= ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>arithmeti= c, the factor of 2 that she cited in her response to Mr.</span><br></blockqu= ote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>J= ager tells us nothing about his assertion?</span><br></blockquote></blockquo= te><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><br></bl= ockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><s= pan> 7.3. Do all members of the TLS Working Group now agre= e that Mr.</span><br></blockquote></blockquote><blockquote type=3D"cite"><bl= ockquote type=3D"cite"><span>Jager's assertion is true? To wit, when someone= downgrades from the</span><br></blockquote></blockquote><blockquote type=3D= "cite"><blockquote type=3D"cite"><span>protocol that the group recommends, X= 25519MLKEM768, to the new</span><br></blockquote></blockquote><blockquote ty= pe=3D"cite"><blockquote type=3D"cite"><span>MLKEM768 alternative, the benefi= t measured in CPU cycles saved is</span><br></blockquote></blockquote><block= quote type=3D"cite"><blockquote type=3D"cite"><span>negligible both in an ab= solute sense and relative to the cost of the</span><br></blockquote></blockq= uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>forgone secur= ity induced by the downgrade.</span><br></blockquote></blockquote><blockquot= e type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></bl= ockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>The discu= ssion of questions 7.1 and 7.2 will be of interest mainly to</span><br></blo= ckquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><sp= an>members of the group, but question 7.3 matters to people who have to</spa= n><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span>make a decision about which PQ key-exchange protocol to adopt. A= s</span><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote t= ype=3D"cite"><span>things stand, they now have reason to treat the TLS Worki= ng Group as a</span><br></blockquote></blockquote><blockquote type=3D"cite">= <blockquote type=3D"cite"><span>hesitant, unreliable advisor that for inexpl= icably, refuses to answer</span><br></blockquote></blockquote><blockquote ty= pe=3D"cite"><blockquote type=3D"cite"><span>question 7.3. A pivot to more ac= tive moderation could further</span><br></blockquote></blockquote><blockquot= e type=3D"cite"><blockquote type=3D"cite"><span>undermine their trust in the= group.</span><br></blockquote></blockquote><blockquote type=3D"cite"><block= quote type=3D"cite"><span></span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span>The proven way to build trust i= s to have an open discussion that</span><br></blockquote></blockquote><block= quote type=3D"cite"><blockquote type=3D"cite"><span>addresses specific quest= ions and converges to a clearly stated</span><br></blockquote></blockquote><= blockquote type=3D"cite"><blockquote type=3D"cite"><span>consensus about the= answer. Question 7.3 might be a good place to</span><br></blockquote></bloc= kquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>start.</spa= n><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span></span><br></blockquote></blockquote><blockquote type=3D"cite">= <blockquote type=3D"cite"><span></span><br></blockquote></blockquote><blockq= uote type=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote><= /blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span= ><br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D= "cite"><span># References</span><br></blockquote></blockquote><blockquote ty= pe=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></blockq= uote><blockquote type=3D"cite"><blockquote type=3D"cite"><span> = - I have never been able to confirm whether Fermi made the</span><br><= /blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"cite"= ><span>statement I attribute to him in section 1.</span><br></blockquote></b= lockquote><blockquote type=3D"cite"><blockquote type=3D"cite"><span></span><= br></blockquote></blockquote><blockquote type=3D"cite"><blockquote type=3D"c= ite"><span> - The characterization offered here of the dis= cussions that</span><br></blockquote></blockquote><blockquote type=3D"cite">= <blockquote type=3D"cite"><span>sustain science relies on _The Knowledge Mac= hine_ by Michael Strevens.</span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span></span><br></blockquote></block= quote><blockquote type=3D"cite"><blockquote type=3D"cite"><span>____________= ___________________________________</span><br></blockquote></blockquote><blo= ckquote type=3D"cite"><blockquote type=3D"cite"><span>TLS mailing list -- tl= [email protected]</span><br></blockquote></blockquote><blockquote type=3D"cite"><bl= ockquote type=3D"cite"><span>To unsubscribe send an email to tls-leave@ietf.= org</span><br></blockquote></blockquote><blockquote type=3D"cite"><span></sp= an><br></blockquote><blockquote type=3D"cite"><span></span><br></blockquote>= <blockquote type=3D"cite"><span></span><br></blockquote><blockquote type=3D"= cite"><span>--</span><br></blockquote><blockquote type=3D"cite"><span></span= ><br></blockquote><blockquote type=3D"cite"><span>Sophie Schmieg | Informati= on Security Engineer | ISE Crypto | [email protected]</span><br></blockquo= te><blockquote type=3D"cite"><span></span><br></blockquote><span></span><br>= <span>_______________________________________________</span><br><span>TLS ma= iling list -- [email protected]</span><br><span>To unsubscribe send an email to t= [email protected]</span><br></div></blockquote></div></body></html>= --Apple-Mail-BCB793CB-0196-4C4A-BE88-87910BB86FCD Content-Type: image/png; name=wikipedia.png; x-apple-part-url=593C86C9-9902-4D00-A139-4C20B85AC11A Content-Disposition: inline; filename=wikipedia.png Content-Transfer-Encoding: base64 Content-Id: <593C86C9-9902-4D00-A139-4C20B85AC11A> iVBORw0KGgoAAAANSUhEUgAAAKAAAACgCAAAAACupDjxAAAE6ElEQVR4AezOAQEAAAQAIP9PMwPU giKHExQUFBQUFBQUFBQUFBS8GRQUFBQUFBQUFBQUFBQUFBQUFBQs4szAQ5UujMN/1I+RiLEkElki RMRHCCEilhDiYkNEliyEi3AJIQsXi2VZliAkiwhZWWGM33dvzrzONHMWbjPzAJz7+R4z5zzvmfa/ m0KpWm92evejx+lkPOi1G7VSPmvndjzl7Wyx+mdp8DB9GPa7rUatXMzmPugUU3a+XG/3huPxsN9p VPJ2qkIurfTNn3/fvR89jAbdZrVgp0r/LpiDgVceLYTxzC2ClMkHBLj9d8H3fjnEw64PvsinTj7w f2wNj3Qf7yrQSdcGK/Jj2C5Aw6rcb66yB4/LW/jIzxwqNg1otNf0WLfgUZjLP3cXedEbHa93SJxp GgIKB2rMND9quJ760KHGKqVe+ea6p/hFM3yjj6EsPPn/E5wZ008Xf8nvr52ZX/DIuPThlKBYUOeI v7R4wVSdpKt3UPZUIA3PUPygzg4Asp8UtC3RjSDU25R3JB1e4O22mxM1fgfeuuyI9C4CQf6AYhlI ERRzanQANEPKL4/62oIfXg8bND3CMgXuLcAKHtWDBVgfkQiyA8UmcMah+E1hIE8qcEY6jEbwDYo+ L6mqlSo99mkgc2CAW+nU9QVZ8UITmAFLKF70HTsiw058hVEJSgunvMD1hmHda0wKsI/hsZpHJniy lUbRDdZN8c4zPQATBthZQNaJTJCDwGEQ9yygTY6tBeRODI3giNEJflOaCRRrkrwD8JMBnCxg7SMU ZNNYms+MWrkjubaAgsMAC7UeneCzuTT3asX6MB+FmmzSqAR5ayzNzhL3FYCSywArKWV0glNjadhV K6l9Iziw5WjPIxY8ZoylWUNRN8T4mJbGRCfIvrE0bELAs+Hpjxm14BrG0rxC+M+wf6195IKsG0vD KjxeDQW4Y/SCSymNealu+mZ4j0HQyUtpjFeGvBM+hquMQZATc2lmwbu/MAKwiEXwkJLSGK8MJTds DOecWAR5J6UxP91l2Bh+YDyC71Ia81Il5GMutY9JkFVjadqmUq/laz0OwbmpNGsI9eAYXsUmeLox lKYFAW+XI7zG2AQ5DJRGdqC8/ublGF7EKLizQkvTAKxtQ7v7CyVpTDyCbIWV5u28K1+g6FB4kcbE JSgWDf81Ir2nnHFrqx/u1CFWQZakND7poX5l6Om/I3UZr+BPKY2eYvuTpFuUu782hlcxC35lpDTa de/Rf2W45xknJzfY+AT547I0VfktQa4MmYOM4WXsghv4S/MEYHZ5ZRh77z7vxC7Ihr80ZeDWufyV wf5S82/C+AWffKVZ+l7jQH//fSB9SEDQLWilcUtAJWTS5JzzGO4yAUE+an8emV9csLpQzM5BWiUi eEhLaZwiUA+9dxWdkjQmXkH9MU1/Bb4omzJOZHPGL7iSx1QA2sZfGaQxsQuyBsHamNcmTEpwAaFn qpA0JglBJysSO/N9p8fEBDmCYvDNH1XWCQruVZDtAwM4Ofm8S06QbTkGxpA/JScoNcmeGMLRPjfG TVSQZQD4+c3H6SOTFZydx5lhh6aA9GfCgif7my/ynjQmOUGOv7kKbO30JnFB7lwa+Tr+364dCwAA AAAI87cOo2cRDCD/ICAgICAgICDgEyAgICAgICAgICAgICAgICBgYUeNfR+Kw20AAAAASUVORK5C YII= --Apple-Mail-BCB793CB-0196-4C4A-BE88-87910BB86FCD-- --Apple-Mail-5B35E89B-F2F0-4FA8-B937-116566B5BD8F-- --===============6564392036496953847== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVExTIG1haWxp bmcgbGlzdCAtLSB0bHNAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byB0 bHMtbGVhdmVAaWV0Zi5vcmcK --===============6564392036496953847==--