Thank you, Chris, for the pointers! I wasn't aware of the paper nor the
GitHub issue.
It's such a coincidence that I'm reading Shrimpton's 2004 paper on
IND-CCA3!
I noticed you are one of the authors of the paper you cited. That makes it
even more interesting :)
Katz and Lindell (Third edition)
HI Devi,
This decision was made in large part due to the (arguably too conservative)
analysis in this paper: https://eprint.iacr.org/2018/634
Here is the issue where it was discussed:
https://github.com/tlswg/tls13-spec/issues/1145
I don't know why the AD was empty ... I'd also be very interested