[noise] Ciphertext-indistinguishability from random noise with Poly1305?

Alex alex at centromere.net
Wed Feb 14 20:33:18 PST 2018


On Wed, 14 Feb 2018 17:53:49 +0000
Trevor Perrin <trevp at trevp.net> wrote:

> CON:  It's an unnecessary requirement for an AEAD scheme.  Somewhere
> down the line someone might show up with an AEAD that doesn't fit this
> requirement but is otherwise good, and we will then be in the awkward
> position of disallowing their AEAD for a superfluous reason that is
> irrelevant to their use case.
> 

Can we use "SHOULD" here? Why does it have to be all or nothing?

-- 
Alex


More information about the Noise mailing list