> On Dec 7, 2018, at 4:10 PM, Joe Touch <touch@xxxxxxxxxxxxxx> wrote: > > > >> On Dec 6, 2018, at 2:40 PM, Eric Rescorla <ekr@xxxxxxxx> wrote: >> ... >> And of course TCP-AO doesn't attempt to provide privacy. This is why routing folks were sent in that direction.. > It can, by changing the association parameters and packet processing algorithm, without changing the rest or the protocol. > > See draft-touch-tcp-so-encrypt Sure, the issue still is we need running code for TCP-AO and it’s not yet available. - jared