MLS v2: More Layering Stuff

Is someone taking notes? Richard is the note taker for the rest of the session.

surely \"Decrypt later\", not encrypt :p

@Meetecho Robot can Rohan be made a little bit louder?

Sending someone over

thanks! It's not terrible, just a little subtle

this should probably use AES-256 and SHA-512, right?

I like mahy-mls approach

TL;DR: it appears that running Grover's algorithm will be super expensive in practice

Possibly. But given the low cost and omni-present HW acceleration of AES-256, there's no reason to downgrade to AES-128.

Webex uses AES-256 for all media (basically just to make the PMs happy), and I've never heard performance complaints

", "time": "2023-07-28T00:27:10Z"}, {"author": "Nick Sullivan", "text": "

This also mirrors earlier discussions about whether or not there should be different levers for different cryptographic operations like TLS 1.3 or not.

", "time": "2023-07-28T00:27:13Z"}, {"author": "Richard Barnes", "text": "

(reprise from IETF 116)

", "time": "2023-07-28T00:27:19Z"}, {"author": "Richard Barnes", "text": "

+1 to Raphael

", "time": "2023-07-28T00:28:20Z"}, {"author": "Richard Barnes", "text": "

finally consumer reports is covering group key exchange protocols

", "time": "2023-07-28T00:41:26Z"}]