________________________________ From: Eric Rescorla <[email protected]>
> On my M4 Mac, X25519+MLKEM keygen is about 41us, seven if I did 10 of them > for each connection that would be less than 1ms of CPU time. > This is a relatively fast but not ridiculous machine, but even if it were 10x > worse, > that still wouldn't be a meaningful number for any client I am aware of. My team supports some apps on phones back to Android 5.0 (ca. 2014), which can be even slower than that. On that class of device, performing 8 keygens ((QUIC+TCP) x (IPv4 + IPv6) x (Cell + Wifi)) might add up to several milliseconds, which would probably be measurable (though certainly not perceptible). However, I agree that under more reasonable assumptions the value is negligible, and is generally outweighed by the linkability issue. --Ben
_______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
