[noise] Chaining variable

Stephen Touset stephen at squareup.com
Fri Jul 11 00:47:51 PDT 2014

By my reading of the spec, when a client receives the first noise box from
a server, the server does *not* send the chaining variable to the client.
The client now needs to call the KDF function four times in order to
compute the chaining variable for the noise box it responds with.

Is this correct?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20140711/f8c3bfd6/attachment.html>

More information about the Noise mailing list