Re: [CFRG] NSA vs. hybrid

"Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com> Sat, 13 November 2021 18:50 UTC

Return-Path: <sfluhrer@cisco.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 536883A07CA for <cfrg@ietfa.amsl.com>; Sat, 13 Nov 2021 10:50:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.596
X-Spam-Level:
X-Spam-Status: No, score=-9.596 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=fW7i+Lgv; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=RVJ/qesu
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DFyEZyd5M6My for <cfrg@ietfa.amsl.com>; Sat, 13 Nov 2021 10:50:29 -0800 (PST)
Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A6D613A07F4 for <cfrg@irtf.org>; Sat, 13 Nov 2021 10:50:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2588; q=dns/txt; s=iport; t=1636829429; x=1638039029; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=MlkIa9mY7k33HFd1PPJ/HQRjJT5hXwyksgyRGQMksGU=; b=fW7i+Lgvw6NBPcTCIIyQtHrdsJwHANo2mphN8YK8gjkk1Wtuu69wDO2s cLVexvtFen8bYuktAxUQ7SABPijIqcfuizNImx3jZa+Blox2xAZdSCUUR NF6saFvV0a/3SMxqUDvfx+UQRsqL4qRCSd2L306AT0PRiG6El1ZKJZVAf 0=;
IronPort-PHdr: A9a23:0w9OMhUCITEepcyAtysB4/nI50jV8K36AWYlg6HPw5pCcaWmqpLlOkGXpfBgl0TAUoiT7fVYw/HXvKbtVS1lg96BvXkOfYYKW0oDjsMbzAAlCdSOXEv8KvOiZicmHcNEAVli+XzzMUVcFMvkIVPIpXjn5j8JERK5Pg1wdYzI
IronPort-Data: A9a23:J09EWq6LxQAZoaiFg90p8wxRtAzFchMFZxGqfqrLsTDasY5as4F+vmQfDDjXOv+JZTb2L9okPYTnphtV68WHm9AyGwE4+y09Zn8b8sCt6fZ1gavT04J+FiBIJa5ex512huLocYZkERcwmj/3auK49CAljvnSLlbBILes1h5ZFFcMpBgJ0XqPq8Zh6mJZqYDR7zGl4LsekOWHULOR4AOYB0pPg061RLyDi9yp0N8QlgRWifmmJzYynVFNZH4UDfnZw3cV3uBp8uCGq+brlNlV/0vD9BsrT9iiiLu+LgsBQ6XZOk6FjX8+t6qK20cZ4HdtlPdgcqNBNC+7iB3R9zx14M5DsYGwUwozFqbNg+8aFRJfFkmSOIUXpuWdeCbh75P7I0ruNiGEL+9VJEo4J4Iw+/xrDydJ7/NwACsRYwiDiuTwzruhUORoguwoN4/3N49Zu3wI8N1zJZ7KWrjZSKnMoNRfxjp12oZFHO3VYIwSbj8HUfgJWDUXUn9/NX70tL7AaqHDTgBl
IronPort-HdrOrdr: A9a23:dMunNaw7B3O9ciUB0qg6KrPxh+skLtp133Aq2lEZdPULSK2lfpGV8sjziyWatN9IYgBdpTnyAtj+fZq6z+863WBxB8bsYOCCgguVxe5ZnPPfKlHbakjDH6tmpNpdmstFeZzN5DpB/L3HCWCDer5KqrTqgcPY59s2jU0dNz2CAJsQiDuRfzzra3GeMzM2Y6bReqDsgvZvln6FQzA6f867Dn4KU6zovNvQjq/rZhYAGloO9BSOpSnA0s+7LzGomjMlFx9fy7Yr9mbI1ybj4L+4jv29whjAk0fO8pVtnsf7wNcrPr3OtiFVEESvtu+bXvUkZ1SwhkFznAhp0idtrDD4mWZkAy200QKJQoj6m2q05+Cq6kdR15ar8y7ovZKkm72jeNr/YPAx2L6wtXDimhAdVZhHodJ29nPcuJxNARzamiPho9DOShFxj0Kx5WEviOgJkhVkIMEjgZJq3MQiFXluYdw99ePBmfQaOfgrCNuZ6OddcFucYXyctm5zwMa0VnB2GhudWEANtsGczjATxRlCvgcl7d1amm1F+IM2SpFC6eiBOqN0lKtWRstTaa5mHu8OTca+F2SISxPRN2CZJ0jhCcg8Sj/wgo+y5K9w6PCheZQOwpd3kJPdUElAvWp3YE7qAd3m5uwDzvkMehTKYd3A8LAt23FJgMyKeFOwC1zxdLkHqbrUn8ki
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AsCQBaCJBh/5tdJa1agQmBWYFSKSgHgVE3MYRHg0cDhTmFDl2CJQOQKopiglMDVAsBAQENAQFBBAEBhQQCF4JJAiU3Bg4BAgQBAQESAQEFAQEBAgEGBIERE4VoDYZCAQEBAQMSEREMAQE4CwQCAQgRBAEBAQICJgICAjAVCAgCBAESCBqCLheCYAMvAZ8yAYE6AoofeoExgQGCCAEBBgQEhQoYgjUJgRAqgwyEHIcEJxyBSUSBFUOCZz6ELQkRFYMBN4Iujx4BXwGBKzBIMAc2agMCApVVqSAKgzmfHxWDbKNAlhQfgiGeEiyFBQIEAgQFAg4BAQaBdyWBWXAVgyRRGQ+PRgELgkCKXnQ4AgYLAQEDCY0XLYIXAQE
X-IronPort-AV: E=Sophos;i="5.87,232,1631577600"; d="scan'208";a="962216667"
Received: from rcdn-core-4.cisco.com ([173.37.93.155]) by rcdn-iport-6.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 13 Nov 2021 18:50:28 +0000
Received: from mail.cisco.com (xbe-aln-003.cisco.com [173.36.7.18]) by rcdn-core-4.cisco.com (8.15.2/8.15.2) with ESMTPS id 1ADIoSZ1004814 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=OK); Sat, 13 Nov 2021 18:50:28 GMT
Received: from xfe-rcd-005.cisco.com (173.37.227.253) by xbe-aln-003.cisco.com (173.36.7.18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.792.15; Sat, 13 Nov 2021 12:50:27 -0600
Received: from xfe-rcd-001.cisco.com (173.37.227.249) by xfe-rcd-005.cisco.com (173.37.227.253) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.792.15; Sat, 13 Nov 2021 12:50:27 -0600
Received: from NAM02-SN1-obe.outbound.protection.outlook.com (72.163.14.9) by xfe-rcd-001.cisco.com (173.37.227.249) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.792.15 via Frontend Transport; Sat, 13 Nov 2021 12:50:27 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=S1JJmADBSMLnpqz+YH/zyLyO9sSPXZVjT+TpuouUlybb8T/ayJkj9lttO68pYf7ARfV6pSjkDXJPAjIGti1aHeWPTWgahuiSaXETyy10OkLYAtasvv8cYdswzQSHKl9t8SjtL6lzz1lfpvwza+6m62cjIY6OILOu8ASAlc07Y/LqBVvuRIk6u3WsFab0a7liTP2yW5KmAf0lwHRY7tb2qOWS8wdQ2hcQUcLrJTEhjSP5Btn5b6ryCc6xx3H6MeHO6xu722Wt/c9sT3SFl0+WWBu0Q8WEQxBKMikizzncqdKPLmO05GWzscHRpTDMJU05q3sGjEE5iscI/wLdsTpNWQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=MlkIa9mY7k33HFd1PPJ/HQRjJT5hXwyksgyRGQMksGU=; b=Y4vVMhYovDdwva2F7tlOreU84+ZIY1WX2YyZR4IyxMZUOiKOaM5ordhp+/5fxIhvW640iYIXipT7hMW/xkdWTBPYLnW+DXwb5gsY6qyiJd0Tsk4/Wkx3GyuRRcozKOCF+XFX7CmbQi0tgfi5BdawX0RxNmYnf9SzNYCc7WMJFvTAm2iG+m7J5Vbb71Y2ErZtKUCV0RYxOm5X/MawezQ/MAiXs9OAmejDf5sYdl/mnV/Utn3KatmQ6slg2Qwu55bjGNwOWE6xpxHrJ4yz7xdIkL9lOyRl5l3eb34Rej691HBA8uBwMSNnQFukjilbKM8BnB47/FCmlhCmtP4iPxa9rg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=MlkIa9mY7k33HFd1PPJ/HQRjJT5hXwyksgyRGQMksGU=; b=RVJ/qesubFS74G7vUxNW3PlppVhmgZ6Kq9+bFSsTSXkixqFD20Fk9xclGfLoENNYdgz2jzOJUbo8YnhbGRPUqLU4sKtQrjmUizBx2gc5ZXiA16+BteI5/zmuLQhjR7RoK9XRp4nAdkC5Wl5zzonVJ9fqk/6fcVztUUoR+iGLd7k=
Received: from BL3PR11MB5682.namprd11.prod.outlook.com (2603:10b6:208:33d::18) by BL0PR11MB3314.namprd11.prod.outlook.com (2603:10b6:208:6d::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4690.16; Sat, 13 Nov 2021 18:50:25 +0000
Received: from BL3PR11MB5682.namprd11.prod.outlook.com ([fe80::7967:f6c7:1632:1549]) by BL3PR11MB5682.namprd11.prod.outlook.com ([fe80::7967:f6c7:1632:1549%7]) with mapi id 15.20.4649.020; Sat, 13 Nov 2021 18:50:25 +0000
From: "Scott Fluhrer (sfluhrer)" <sfluhrer@cisco.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, "cfrg@irtf.org" <cfrg@irtf.org>
Thread-Topic: [CFRG] NSA vs. hybrid
Thread-Index: AQHX16fCYf0yL9OHnkaLCZQcCyf3e6v/vjuAgAANKYCAABpbgIABlqqAgAARxYCAAD2d0A==
Date: Sat, 13 Nov 2021 18:50:25 +0000
Message-ID: <BL3PR11MB5682D62D1ACE073188D839C1C1969@BL3PR11MB5682.namprd11.prod.outlook.com>
References: <20211113135339.770521.qmail@cr.yp.to> <9cffc5cd-a844-7311-6fd9-80691b4b10e6@cs.tcd.ie>
In-Reply-To: <9cffc5cd-a844-7311-6fd9-80691b4b10e6@cs.tcd.ie>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cisco.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 2124eac2-8a0b-4b47-c8cb-08d9a6d6746a
x-ms-traffictypediagnostic: BL0PR11MB3314:
x-microsoft-antispam-prvs: <BL0PR11MB3314EA71A30D233D047DEE18C1969@BL0PR11MB3314.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: VBDZD5Gel100yfoPQbXXC8ga5pM6GE9wFiU4JCGZydzo+L0ZObCfqKf650RQCjct5+PkUW13DcD89cKjnT2lDxZfYd7EBM285OfHpBx3FTT0pdeZW4JyxaiQNCehCziyxI62qAf13H4uIzLftiIlcnZe3x23R5NRuSbvb1uPbC9H3x6QZ6NqKtHz9kaoxzKN1YV9XHpekJGWLoyt33Fnhw0LCxbujZRi5tS/Rn4td/jfzC0LnvRUx6/ZXjSW3ZSd3jdfp4K6ZhGVvpiPfo6G1uByxHiMB8vuYK1QDUcqkXGE0wPrLQC2mIKgfNU2bNRlCh1WfjEnnoFm0FNopFgF9hTH4ta8kaeNOQFd3fgPNFMrfKmEnH4+CUM1kPVMJBL3QHVQI5oyle/Cg3tDNzKYPMphJajasdd0OXIuiApHMavrCnWP4a6g8rwasUECbPxQLT2/XjrUJD0lkoSo9Wwzn8XGv2wRjmxD2L23TjVmyVfanzopfTp2QxObt+0ZEaTzGibdMFDwKLB98E31paEkN0ycBsTqAYAljpNN5V0niF8OM8kquzXAUpC8SDU+0w00lUAlnWJrlKbbb694O6HFqM74fth9054FJqtMDKYlfzNHKJvzHrk/oY9tjUM8U9v0ZhLaHSGea5AWSXyujOi8RMiLxUyA74ULpVQNrNTRLzPRBWOzVnVBs3xcaK4i9f2/9RYvG/It6bX28JAIJ7iiXw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BL3PR11MB5682.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(366004)(33656002)(83380400001)(6506007)(8676002)(7696005)(38070700005)(26005)(186003)(86362001)(66446008)(9686003)(53546011)(508600001)(66946007)(122000001)(55016002)(110136005)(66556008)(8936002)(71200400001)(76116006)(66476007)(5660300002)(52536014)(38100700002)(2906002)(316002)(296002)(64756008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: /ICh42ufaUeD/EYjvkrTqYdOSSS9JJpa/1E44pwDQi8eqsNSrmujKJzZyP/S931vWngS5FeUbpFaYBKkBA99qMxKniZuee0q6qtAqywcB92PYxRkopaJoXoPcaL8xi2Uw5yXOMHlWsWpi94wrSkCxal8x3xhqBKsydPnLX478IbraXolurRK3XBK3tycZ5W/tTw1MVZWlRc4M9tULpBHqubKWyZmuG/Ex67qBQAFvuXX+0WTiJW5Q41P+rqnm+coO0B3lhcaaDmwspt3sBGxEHPRu++nPwLf0OJfUhd85QuQ2hf/SLDx0CXpq4e/UuCZbaZR4iuWMAlMLWXUhZfyGMsI1Yext7LCORoyuhTJu23M+wbcVrfg1GqKzkjOJFz6wrCuTAIUJZPNYB+0w32JB4udKkvZOeYsFy2c1eLfZZYy6LSaPOVoABYbuHik4Yyh0ZT8LQssyP0BCfg0nHiSHlyIutTOUE7H0Tc08EIPqwUmhflsLJw7dpng0UBK+Le0aZpa5r6kXk8LRAgnA5k//f22oKc24mFN0RIs8v1fC8lyx1p5MkD/GTgpVU4h2RNs5eXomK/71l0XtXvxNzjThC3ED92aVArFjpOibHihGO8o0H63ulK8u2BxF4+4fta2UvVUVmvt7NDxO0BrB0USeXl30KLYyiu+YRU8cEpGazOyVXUVtz8fbGu75dmeLPYTytn8URQi0WbqmMt7CZV+PxA82OgkrRZFKciVaVKjoOUCjATPWaBeLsXsTCCs2SV45xTjNx9F/AneaB1zmrMSPluW073rcnC3N0tvXDtawokQ63EG1mlDaM0hlYozjI2r9fTTkSk4IzLS5+HQ8zNXXR5OrvL6YaK/yyDGYyjbCe/p8QuGMvN3V0l1P4jz3H+7Ao9ZXwBQ5ZXkBa6uF8l6KXTf6ofZBXI9rZOd29CZKsNSGpNUvHEzvQKh1cfHSxQgVFHdISELbJdMbozTN51z9/odwDCPuSVZIxGxHMz+5B93fCPqknoZtx8oyb1wxCwjf/g0RqKoKSqLxZkbde2hI+UjrS/DL8gBTTYYcfkcEGl4JluwqRdk5rK80abv4QSw1CA54JFA0fnstMp7hZexbVz7kdYdYb2ofWY82dYZqYwxVmwgWVhhPPxcgmCoHyYwTeLGDkKQPLcRTkxMgnUlBJ9z+lhYm1sHVRLzZ3VEOiwXXryNW5ewfHMuk1h/CNdthQtmZc8tghihA4rP9Nv5upghLzUkmy0P2t/gze3Ao8x6IXUbauu30hZb5K1jxsRBHoiYhJ4HGDAJOUmNP8XZU+fBZPhosQADNvsCA/tcYLoTbaTZo0CuK0tXKKKjsIOLJknslxS30ee2uchPIlruJfwstDROQLlxk0SzIFJcefaoE2BAYSO6H/xIsPBJZv/ZoE+kHm+GS21PltyEfsTy1vt7cRPoB5GVHcHY3kVifuG4LYdLfRuDsHsHx5nNn/YCxw1hJXmrOTwDmoHciY8N/kyAvK3GsrNCHvNjtiLQ/MofyGTsqPo6DEDcPT2+H73SWUUM+ViSOdNMy8HS0MwNo/pptpeQkWVL7hQmmMZZwSlwszmYSZxj9MGVnZ6w6c0cgP9mLBpUayr+TgBAjAqs0g==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BL3PR11MB5682.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 2124eac2-8a0b-4b47-c8cb-08d9a6d6746a
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Nov 2021 18:50:25.4360 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: sBEoAi0uL58I9oyKTbdQLAvaRCsiNy/6Ddyk0vXgouuHGjdbdjWI1HWVSHTxIvpAYTkFVHZoTK4moLiGtseU6w==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL0PR11MB3314
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.18, xbe-aln-003.cisco.com
X-Outbound-Node: rcdn-core-4.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/Y0EhL42SRiouW_nRF_7A15ryrYA>
Subject: Re: [CFRG] NSA vs. hybrid
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Sat, 13 Nov 2021 18:50:34 -0000

While I agree that updating TLS with new KEMs doesn't have to be done at the same time as we update the certificates, I don't believe we want to take too long.

One complication that certificates have over KEMs (in the context of TLS) is that there are more parties involved.  For the KEM, we need to update the client and the server; once we do that, the client will propose the updated postquantum 'groups', the server will accept that proposal and we are good to go.

In contrast, to update the certificate, we also need to get a third party involved (the CA, which needs to issue both the new postquantum certificate root, as well as the postquantum certificate to the servers - there may be even more parties involved, if the RAs are run by separate entities).  Because there are more parties involved that all need to be upgraded before we're protected, we can expect the timeframes to take longer.

Hence, even though postquantum authentication might appear to be a less urgent need, the task of upgrading could plausibly be expected to take longer.

-----Original Message-----
From: CFRG <cfrg-bounces@irtf.org> On Behalf Of Stephen Farrell
Sent: Saturday, November 13, 2021 9:57 AM
To: cfrg@irtf.org
Subject: Re: [CFRG] NSA vs. hybrid


Hiya,

I think I'm in general agreement with djb on this. One note though...

On 13/11/2021 13:53, D. J. Bernstein wrote:
> I agree that certificate validation is a mess.

For protocols like TLS (likely to remain the most important for quite a while) I don't think we need care about changes to the web PKI for a much longer while. Maybe we should add some PQC algorithm into some TLS handshakes soon, but there is no need to change the PKI for that in the same timeframe.

In general, I'd be for slowing down much of this transition stuff, and having CFRG opine to that effect might be a good thing.

Cheers,
S.