[TLS] Re: Discussion about the Deployment Decision
Paul Romer <[email protected]>
| Newsgroups | gmane.ietf.tls |
|---|---|
| Message-ID | <CAEzBKQ4aj=bac9i1wjCZGMKZQDh1NW4R-QrX8UdSTGwrvnZCsg@mail.gmail.com> |
Rich, You wrote: > We don’t need a consensus call around "some folks will ignore our RECOMMENDED=N” we > know it as a truism. Such folks have their reasons. 1. Consensus I think there is a misunderstanding here about the meaning of consensus. It is easy to correct. - When I wrote about "reaching a consensus", I did not mean going through the IETF process of having a consensus call. I agree with you that implementing that process would be a waste of time. - What I was referring to when I used the word "consensus" is a general state of agreement among the members of the group. For example, there may well be a consensus that "some folks will ignore our RECOMMENDED=N" flag". - When there is a consensus, it helps to put it in writing, just as you have done in this case. This helps cut short any subsequent cycle where someone makes an argument that includes "because everyone will follow our RECOMMENDED=N flag, ..." The easy response is that "we don't need to consider this argument because we already agreed that P is true." - On the more general point about reaching a consensus, in many cases, apparent disagreement is caused by misunderstandings like this one. A good discussion supports convergence to a consensus because it clarifies misunderstandings. 2. Risk For a readable explanation about how to think about risk, take a look at Chap 5 of "Robin Hood Math: Take Control of the Algorithms That Run Your Life" by Noah Giansiracusa. Noah is a Ph.D. mathematician who writes very clearly. 3. Smart Cards The reason I recommended going from an estimate of the average savings from downgrading from X25519MLKEM768 to MLKEM768 to a distribution is precisely because there are many devices and the savings will vary by device. To go beyond whataboutism--"What about smart cards?", "What about mobile?" "What about YubiKeys?" ...--we need to start with estimates about how often various devices do the calculations required to set up a TLS 1.3 connection and measurements of the computational resources required to do the calculations for X25519 are on each device. From this data, one can construct the distribution and use it to give a more complete device specific analysis of the decision about which of the two protocols to deploy. For TLS connections, I imagine that if a smart card is involved, it is used in conjunction with some other device that has a network connection. To consider that case, we'd need to know about the other device. _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]