Has anyone got any numbers on the actual computational cost of perfect forward secrecy so that we can make a more educated decision? Has anyone considered Yacobi's scheme that he published in crypto a couple of years ago?