[noise] Hybrid Forward Secrecy, version 1draft-2

Rhys Weatherley rhys.weatherley at gmail.com
Tue Sep 27 18:15:48 PDT 2016

On Tue, Sep 27, 2016 at 7:09 PM, Rhys Weatherley <rhys.weatherley at gmail.com>

> I've been working on the implementation for Noise-C (not pushed yet due to
> a bug in my test vector generator).

The bug has been fixed.  I have pushed my first-pass Noise-C implementation
of Hybrid Forward Secrecy.  Test vectors can be found here:


The vectors check 25519+448 and 25519+NewHope with all ??hfs patterns and

As expected, the only hfs scenarios that don't work the same as basic Noise
are fallbacks involving PSK's.  The encrypted "f" token in the abbreviated
handshake makes fallback impossible in that case.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20160928/bf02af3a/attachment.html>

More information about the Noise mailing list