[noise] Noise HFS Kyber question

dawuud dawuud at riseup.net
Sat Feb 2 20:47:03 PST 2019

Hi Peter, Rhys and the noise mailing list,

I just got Rhys's Noise HFS Kyber extension to work on our port of the flynn golang Noise library:

My question is why did you choose to use Kyber768 instead of Kyber1024?
Maybe this is a question for Peter Schwabe:
How do these (Kyber768 and Kyber1024) compare with the safety margins of NewHope Simple?

The reason I'm asking is because the Katzenpost (https://github.com/katzenpost)
Noise based link layer currently uses NewHope Simple with XX in HFS mode and I'd like
to use Kyber with parameters that will give a comparable security margin.

David Stainton
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20190203/420e0f7c/attachment.sig>

More information about the Noise mailing list