[noise] Hash len > cipher len in tls1.2

Tony Arcieri bascule at gmail.com
Fri Mar 4 20:37:04 PST 2016

Since a hash function is effectively a PRF as opposed to a PRP, you run the
possibility of collisions and therefore have to account for the birthday
bound/pigeonhole principle. For a given security level, you take the square
of the key size you would otherwise use with a symmetric cipher.

Tony Arcieri
