[TLS] Re: Discussion about the Deployment Decision

Paul Romer <romerp@bc.edu> Tue, 04 August 2026 15:05 UTC

Return-Path: <romerp@bc.edu>
X-Original-To: tls@mail2.ietf.org
Delivered-To: tls@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8E7F612370738 for <tls@mail2.ietf.org>; Tue, 4 Aug 2026 08:05:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785855922; bh=bDt22hH1JnEKQlLiYqBXsfX8I3cRMssQewoQpDUMytw=; h=From:Date:Subject:To; b=ijdQvPkKk11JEs4sb2oFPYHgx4AluZ5+NFdQl/xXsgGonTYFxrduL0GCSu4mCvKNe yCLNQcnbXTM5JuapXnk4KTUzZmeqxBN1V773r50lMH8jO2t6m0gxp6w+xMcxRshlGB MU0m9M0Vr7Tsdc2aB9k4VIL1EhTMdBeNh0AkQ/io=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=bc.edu
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OMICCp08FmwW for <tls@mail2.ietf.org>; Tue, 4 Aug 2026 08:05:22 -0700 (PDT)
Received: from mail-pj1-x1033.google.com (mail-pj1-x1033.google.com [IPv6:2607:f8b0:4864:20::1033]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id DEE351236F536 for <tls@ietf.org>; Tue, 4 Aug 2026 07:57:53 -0700 (PDT)
Received: by mail-pj1-x1033.google.com with SMTP id 98e67ed59e1d1-383cb94f742so4765590a91.3 for <tls@ietf.org>; Tue, 04 Aug 2026 07:57:53 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785855466; cv=none; d=google.com; s=arc-20260327; b=B3pXeB1ztPI07XJhenjshXgiIJlrp7yRLxV+xqyXa/RqIo4rRuOV1CuLdg8BOBQ8Vz w5CRtW7knSJYRpFOzK52xJbHlehA5LGUGpHrF5Q8DbQ8Tv8K6gPx9+7H0tZRkYWnJgtZ Zd4THL70TtFLAS6mOY/oXUIY4pr+2DQ0XKJCKAmyetXGwdaFzcdpykr6V1xaw+ZDTK/6 JrH9UpTJ2wd9pIQFFijhqR4jmAxMQQwDnIb7VKtHXV8DdXBBcC+p7bKdeS0L8FUMRanN IHr15Xy4BNqwX0vLaqAod+KS2quLhG2+OdcLPdv3Vio/QNu+sZVJoIZ46iLo30IyhDoN VWjA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:to:subject:message-id:date:from :mime-version:dkim-signature; bh=bDt22hH1JnEKQlLiYqBXsfX8I3cRMssQewoQpDUMytw=; fh=iMQEz7fIE2XtFWqLUMEt8tz+aEDEJVSqHa2ftqd9oME=; b=hPsED4QYXANzZrMWOOmlN+9ynFjlv8vTl2XdCIjrKcv5rCR077mSAD92URWqTSeSYI +VsbzxSC/BOctxqA0gIyMHmt/58/vvBDsvXIkN1jGg3KtNpftYOySmOa1DlRefVvUA+U iftjWHwU1kkhsKpLRIvCyOknJ3LItKMz8p1422FKkufjA4Xw080iwIB4iS9gyfvoKnGZ H/GFPJzI2mlwUqRzsZCPjd296DkB+9E5zOz56lKYgGkgJu+6sfaUDMdbDHg+J/aySsjW jvjT14SUrcgvEPHqRSqQh5WKikIoVICxty9w3F/Tc7FxMBzlCaxmmUuxVeAKo3M9F6lu fkkg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bc.edu; s=google; t=1785855466; x=1786460266; darn=ietf.org; h=content-transfer-encoding:content-type:to:subject:message-id:date :from:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=bDt22hH1JnEKQlLiYqBXsfX8I3cRMssQewoQpDUMytw=; b=LhPMzpE6daL3tPDYMwOJ2IyE44PRg2hzy0M2vcb+2RGPZEDSZnEQv4NL9YMbKxHJ6C 0vxjOjvzedgKIlVMSWSPhNkoK4mlaDkS5K9jtRuCDqEj8VV7OTsVlnwcFBWsk/JI5tle TCtYVDT4iHnsxMKRP6pnY2EHTKDAvstoEQNrVUMdxVRFSUCZWaZWzH2ogOz4ZlOJcfIC 0kXKVl/WmHsksVVMPpIf+yaGTVk/xIPEfRqmo9cDDYP1x8gtKW8lAwWqUjP8lf4UGmwq ow00reyfsVkhh/LMvFnLnNwRZO4W5imFhuPamNeD18jea3NIycAwO1yMijtAN03ue4m4 +nsg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785855466; x=1786460266; h=content-transfer-encoding:content-type:to:subject:message-id:date :from:mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=bDt22hH1JnEKQlLiYqBXsfX8I3cRMssQewoQpDUMytw=; b=agaT8lVEosyYqP4dqUfa+rpUEV3acrAjrYWmD+4VyX0xKTTOgyK1QaxCLvCMcJYLbm es91q6VzVHUkJlnSx6ZZ66+nf9gG4CJVNNOVGcR/6bSgDrFc960e6aCkW3CseqFvGxZu 9qIDxra7wHk27SMWq92HFn9yeMzQM7lpJj0MmNCupjD/Zw7DcTqB1LjEG91+/fF2z+jN bGTuGqg2RozuNBWmTecG62CHi/ca4GbKPyA7qEc/W3Jwijz5LhW6iRt/sHiwKBZAZK4T WaFtYPGRfTcM/d3A3ofpCbd8a7rGnL4g1s1H7gBs8hxkMc8B5oONsJXnqmKI63cJ3/IJ 50Ww==
X-Gm-Message-State: AOJu0YyCX2KGsG0Umrm8jg8aow+8BbZF9p43NoS7qWWVt3zWpCNQ1VjB Vp3Guy8CGtpKoSQi7AHSWp45vsvdsMkg/kh87vocXdf8cARsUNS7ouaz/PzRDdVd6y10wPf4jJ4 DTfEXtESgzxKMBwmqqZt5v9LGCQM8OFGKxGkM5Wf0INWpVPBy2TO2fxhC
X-Gm-Gg: AR+sD12NM/CnN4eGRhuADvTiEckpnl3i1N4AYvG0csbWkOr8FyVo6WRBQGHoAEyN7xv RtpD4zA2LciM9A6Y1lN8UT0XE3mPom0JcsZ6rmNvLY3qnXJtaL3PmXZljCnVkfVw/y3oe29SXID SHq7egXejOgVOgR/IkXQsjysv+pWzjNauQ9uDECJBTsHc+9txmUEcFtrzBjvdbgckN4mu46YxPO wTqDd4HiKG0d+nLlxgZRq/ig+PhuZy9gZEgqnDKhp1u77jPn0ikl0REbkIJPLOAh2fQZT5xwaHP HBBGF5ElHtXFQNv1B08HSVI/cydic0MK2rSmiTJPkC3EHw==
X-Received: by 2002:a17:90b:2dc4:b0:38f:bbc:6a0f with SMTP id 98e67ed59e1d1-38fbc3ff292mr13755928a91.1.1785855466391; Tue, 04 Aug 2026 07:57:46 -0700 (PDT)
MIME-Version: 1.0
From: Paul Romer <romerp@bc.edu>
Date: Tue, 04 Aug 2026 10:57:35 -0400
X-Gm-Features: AUfX_mzD_-pOtY-Wk23LqX53BZhOJOK_zHGThamK29FmPXdnsieafUktODw7xGA
Message-ID: <CAEzBKQ61mvq_t7d9y8tDw-erCz1TrSwkZZCemUwqd3fosz5YDw@mail.gmail.com>
To: tls@ietf.org
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: QTTXDLIPJY4AY5X4XEV4TWZ5N2DJE23B
X-Message-ID-Hash: QTTXDLIPJY4AY5X4XEV4TWZ5N2DJE23B
X-MailFrom: romerp@bc.edu
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-tls.ietf.org-0; header-match-tls.ietf.org-1; header-match-tls.ietf.org-2; header-match-tls.ietf.org-3; header-match-tls.ietf.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [TLS] Re: Discussion about the Deployment Decision
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/kSbXAY82K6yWzNOJiSZs0Jiu4-Q>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Owner: <mailto:tls-owner@ietf.org>
List-Post: <mailto:tls@ietf.org>
List-Subscribe: <mailto:tls-join@ietf.org>
List-Unsubscribe: <mailto:tls-leave@ietf.org>

Rich wrote:

> Paul, what do you want to happen?
> ...
> The IETF expresses an opinion by saying “RECOMMENDED=N”. Many in the IETF recognize that others — often those deploying and purchasing systems — will have a different opinion.

https://mailarchive.ietf.org/arch/msg/tls/i-3dX5MDa-BcGOJWMRrJxs0mIpk/


Rich,

Fair question. Here is what I want to happen:

1. I would like to see the group work its way out of its current "Lord
of the Flies" culture.

2. I would like to see its discussion become more civilized and scientific.

3. In the discussion, I would like to see more assertions about
specifics like the plausible one you make in the two sentences that
I've quoted. If the group reaches a consensus that what you wrote is
accurate, it follows that the people deploying and purchasing systems
are considering other factors beyond the recommendation flag. They
might value any estimate that the group provides of the effect that a
security downgrade from X25519MLKEM768 to MLKEM768 has on CPU cycles
per TLS 1.3 connection.

4. This estimate could be a useful input into deployment decisions,
but to be clear, I would like to see the group work toward a consensus
about this estimate mainly because the effort might be a helpful
confidence building measure as you rebuild your culture.

5. Not everything I want will be feasible, but I also want the group
to consider the full distribution of changes in CPU cycles per TLS 1.3
connection instead of a single location parameter for that
distribution.

6. After recognizing randomness and uncertainty, I would like to see
the group take account of risk aversion, which a simple cost-benefit
analysis neglects. The consensus from decision theory about the way to
formalize risk aversion is to frame a choice as an attempt to minimize
the expected value of a convex loss function (or equivalently, to
maximize the expected value of a concave utility function).


Paul