I think my brain is farting, but shouldn't XK's last message provide a 4 in dest payload security? You can send your own e as the server's response and the client's last handshake payload will have weak forward secrecy David