Re: [TLS] custom lower limit of record_size_limit

2019-01-22 Thread Martin Thomson
On Mon, Jan 21, 2019, at 19:03, Nikos Mavrogiannopoulos wrote: > I do not think that 64 is not hard to implement, but I think it is very > hard to implement it in a way that it is efficient. Totally agree. There's like a curve for performance with an asymptote as records get bigger and a steep

[TLS] Yet more TLS 1.3 deployment updates

2019-01-22 Thread Adam Langley
(This is another installment of our experiences with deploying the RFC-final TLS 1.3—previous messages: [1][2]. We share these with the community to hopefully avoid other people hitting the same issues.) In the last update, David reported our experience with a bug[3] in Java 11's TLS 1.3