Toot

Written by Probabilita on 2024-08-30 at 07:25

@djm Then its probably fine-ish in practice. The point remains that the combiner you are building is not IND-CCA secure. The reason for this is a subtle quirk of the IND-CCA security game that requires ciphertext collision resistance on the ciphertext. x25519 does not provide that because there are multiple representations of the same EC curve point.

In X-Wing, we also took care to use just one sha3 block, so the performance impact from mixing the PKs should be minimal.

=> More informations about this toot | View the thread | More toots from kora@chaos.social

Mentions

=> View djm@cybervillains.com profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113049777757244117
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
232.349304 milliseconds
Gemini-to-HTML Time
0.319526 milliseconds

This content has been proxied by September (ba2dc).