[noise] chacha20 != chacha20poly1305 minus the tag

Jason A. Donenfeld Jason at zx2c4.com
Fri Jul 24 14:52:47 PDT 2015


On Fri, Jul 24, 2015 at 10:53 PM, Trevor Perrin <trevp at trevp.net> wrote:
> Jonathan's request for a Security Considerations section also makes sense.
>
> Other implementation or security advice like this is welcome, I'll
> incorporate it next week.

You wrote a while back: "The exchange of authenticated-encryption
ciphertexts is intended to naturally provide "key confirmation".  But
I need to add some text to clarify when this happens, and in general
clarify which properties apply to which messages." This would be most
appreciated!


More information about the Noise mailing list