[tor-dev] PQ crypto updates

Peter Schwabe peter at cryptojedi.org
Tue Aug 22 18:47:06 UTC 2017


Yawning Angel <yawning at schwanenlied.me> wrote:

Hi Yawning, hi all,

> Ultimately none of this matters because Prop. 261 is dead in the
> water.  Assuming people want the new cell crypto to be both fragile and
> to resist tagging attacks, Farfalle may be a better choice, assuming
> there's a Keccak-p parameterization such that it gives adequate
> performance.

At what number of cycles/block on what architecture(s) would you call
the performance "adequate"?

Cheers,

Peter
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: Digital signature
URL: <http://lists.torproject.org/pipermail/tor-dev/attachments/20170822/0862d031/attachment.sig>


More information about the tor-dev mailing list