[noise] Noise HFS Kyber question

Peter Schwabe peter at cryptojedi.org
Sun Feb 3 00:32:34 PST 2019

Rhys Weatherley <rhys.weatherley at gmail.com> wrote:
> On Sun, Feb 3, 2019 at 3:16 PM dawuud <dawuud at riseup.net> wrote:

Dear Rhys, dear all,

> > duh i just read a section from
> > https://pq-crystals.org/kyber/data/kyber-specification.pdf
> > (at the top of page 17)
> > and now Kyber1024 seems like the obvious choice for Katzenpost.
> > I wonder, Why does Rhys's Noise HFS Kyber spec extension to Noise uses
> > Kyber768?
> >
> It's been a long time since I looked at the Kyber specification, but there
> may have only been a single parameter set at the time or I didn't read the
> specification clearly enough.  Obviously it should be replaced with
> whatever Peter considers the "recommended for wide use" bit size now and/or
> we should define alternative names like "Kyber768" and "Kyber1024" instead
> of using just "Kyber".

That's definitely a good plan. Maybe wait until, say, the end of
February though with changes to Kyber. We're currently in the process of
dicussing round-2 tweaks.


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20190203/09d5a2c6/attachment.sig>

More information about the Noise mailing list