________________________________
From: Eric Rescorla <[email protected]>

> On my M4 Mac, X25519+MLKEM keygen is about 41us, seven if I did 10 of them
> for each connection that would be less than 1ms of CPU time.

> This is a relatively fast but not ridiculous machine, but even if it were 10x 
> worse,
> that still wouldn't be a meaningful number for any client I am aware of.

My team supports some apps on phones back to Android 5.0 (ca. 2014), which can 
be even slower than that.  On that class of device, performing 8 keygens 
((QUIC+TCP) x (IPv4 + IPv6) x (Cell + Wifi)) might add up to several 
milliseconds, which would probably be measurable (though certainly not 
perceptible).

However, I agree that under more reasonable assumptions the value is 
negligible, and is generally outweighed by the linkability issue.

--Ben
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to