[noise] Ciphertext-indistinguishability from random noise with Poly1305?

Tony Arcieri bascule at gmail.com
Wed Feb 14 10:05:01 PST 2018


On Wed, Feb 14, 2018 at 9:58 AM, Trevor Perrin <trevp at trevp.net> wrote:

> The receiver can't do any processing until they have the SIV "tag", so
> doesn't it make sense to put it at the beginning


I think what you meant to say is "it doesn't make sense to put it at the
end" as it prevents incremental decryption which is a good point.

-- 
Tony Arcieri
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20180214/bc4b385b/attachment.html>


More information about the Noise mailing list