Stephen Farrell <stephen.farr...@cs.tcd.ie> wrote: > That'd be a fairly giant outer client hello
Well, is there a latency histogram? The reality I've seen ignored in these discussions is that these large handshake messages are in fact very slow or broken on older implementations, but that it might not matter. The very slow tail in the trailing 5-10% area will never be updated anyway, so it makes no sense to consider them in PQ discussions. For example, we also have folks claiming we must accommodate very old TLS 1.2 implementations. thanks, Rob
_______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls