On Mon, Jan 06, 2025 at 05:18:35PM +1100, Viktor Dukhovni wrote: > On Mon, Jan 06, 2025 at 09:57:42AM +0400, Loganaden Velvindron wrote: > > > I went through v3 of the draft and I was wondering why we couldn't > > have x448 as a "backup" choice in hybrid mode ? > > FWIW, I have an implementation of X448MLKEM1024, just no code point, > to associate it with. Relative performance is not great, and (doing > my best impersonation of David Benjamin) until there's a workable > keyshare prediction specification, it would be very unlikey to get > used. > > keygen encaps decaps keygens/s encaps/s > decaps/s > X25519MLKEM768 0.000053s 0.000070s 0.000056s 18821.2 14208.0 > 17876.4 > X448MLKEM1024 0.000221s 0.000334s 0.000171s 4534.7 2995.0 > 5831.5
Sorry, the original cut/paste failed to fold the lines properly, the above should be more readable. -- Viktor. _______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-le...@ietf.org