[noise] New branch: hkdf

Jason A. Donenfeld Jason at zx2c4.com
Sat Oct 3 08:23:59 PDT 2015


Upon seeing the n0 branch, I had initially thought this too "why don't
you just use HKDF?" and I started writing an email detailing what that
change would look like. By the time I finished the email, I wasn't
very happy with the result. And here, too, I really don't like having
a separate chaining key variable. Noise looses a bit of its simplicity
and elegance this way. HKDF really just isn't appealing anymore in the
face of the previous Noise revision.

Not to mention, this is also a rather late change, and it seems like
we've now put the current key derivation model through the paces in
the last several months. Would be a shame to change gears now to
something less pretty.


More information about the Noise mailing list