[noise] Ciphertext-indistinguishability from random noise with Poly1305?

Keziah Elis Biermann keziah at kizzycode.de
Tue Feb 20 04:27:10 PST 2018


Hi Samuel;
yes, it seems that you're right here. I've also found this: https://crypto.stackexchange.com/questions/17835/are-poly1305-authenticators-distinguishable-from-random-data

So ChaChaPoly fulfils the randomness-criterion…

Best regards and sorry for the false-alarm,
    Keziah
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3256 bytes
Desc: not available
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20180220/968754a9/attachment.bin>


More information about the Noise mailing list