Post-quantum confidentiality for TLS
imperialviolet.org
imperialviolet.org
If that's the case, why go with SL over SI?
So it's a balance between adding an extra ~1.5 kB to the transaction, verses that CPU difference. In different contexts those two costs will have different weights, of course, but my feeling is that in TLS, we probably want to pay for the extra bytes.