[TLS] Re: Discussion about the Deployment Decision

Paul Romer <[email protected]>
Newsgroups gmane.ietf.tls
Message-ID <CAEzBKQ4aj=bac9i1wjCZGMKZQDh1NW4R-QrX8UdSTGwrvnZCsg@mail.gmail.com>
Rich,

You wrote:

> We don’t need a consensus call around "some folks will ignore our RECOMMENDED=N” we
> know it as a truism. Such folks have their reasons.

1. Consensus

I think there is a misunderstanding here about the meaning of
consensus. It is easy to correct.

- When I wrote about "reaching a consensus", I did not mean going
through the IETF process of having a consensus call. I agree with you
that implementing that process would be a waste of time.

- What I was referring to when I used the word "consensus" is a
general state of agreement among the members of the group. For
example, there may well be a consensus that "some folks will ignore
our RECOMMENDED=N" flag".

- When there is a consensus, it helps to put it in writing, just as
you have done in this case. This helps cut short any subsequent cycle
where someone makes an argument that includes "because everyone will
follow our RECOMMENDED=N flag, ..." The easy response is that "we
don't need to consider this argument because we already agreed that P
is true."

- On the more general point about reaching a consensus, in many cases,
apparent disagreement is caused by misunderstandings like this one. A
good discussion supports convergence to a consensus because it
clarifies misunderstandings.


2. Risk

For a readable explanation about how to think about risk, take a look
at Chap 5 of "Robin Hood Math: Take Control of the Algorithms That Run
Your Life" by Noah Giansiracusa. Noah is a Ph.D. mathematician who
writes very clearly.


3. Smart Cards

The reason I recommended going from an estimate of the average savings
from downgrading from X25519MLKEM768 to MLKEM768 to a distribution is
precisely because there are many devices and the savings will vary by
device. To go beyond whataboutism--"What about smart cards?", "What
about mobile?" "What about YubiKeys?" ...--we need to start with
estimates about how often various devices do the calculations required
to set up a TLS 1.3 connection and measurements of the computational
resources required to do the calculations for X25519 are on each
device. From this data, one can construct the distribution and use it
to give a more complete device specific analysis of the decision about
which of the two protocols to deploy. For TLS connections, I imagine
that if a smart card is involved, it is used in conjunction with some
other device that has a network connection. To consider that case,
we'd need to know about the other device.

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.