On 08/04/15 16:06, David Leon Gil wrote:
> If (1), I'd suggest Scrypt(hash=HChaCha20, kdf=Shake255)

Side question: Has HChaCha been formally described and/or proven secure?
There are various bits of code floating around on the net that apply the
HSalsa20/XSalsa20 design to ChaCha to get HChaCha/XChaCha, but does the
XSalsa20 security proof still apply?


