On Tue, Jan 16, 2024 at 08:49:24AM -0800, Eric Rescorla wrote: > On Tue, Jan 16, 2024 at 8:24 AM D. J. Bernstein <d...@cr.yp.to> wrote: > > > To be clear, I think other concerns such as efficiency _can_ outweigh > > the advantages of unification, but this has to be quantified. When I see > > a complaint about "hashing the typically large PQ ciphertexts", I ask > > how this compares quantitatively to communicating the ciphertexts, and > > end up with a cost increment around 1%, which is negligible even in the > > extreme case that the KEM is the main thing the application is doing. > > > > Responding to Dan but really this is a question to the draft authors. Do > you agree with Dan on the approximate overhead here?
I am not one of draft authors, but I tried to estimate the overhead and ended up with in ballpark of 7%. -Ilari _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls