Apples and oranges. H only replaces the +, not the entire round structure.
-
-
Indeed, but one can still look at a cost/benefit tradeoff for the round components.
2 replies 0 retweets 0 likes -
Replying to @ciphergoth @sevenps and
Not knocking NORX, which is very cool! But I wouldn't use its H-op to build a Chor-Chor.
1 reply 0 retweets 1 like -
"Sorsa" was one of our first choices. Even after 20 rounds, it is easily distinguishable from random.
1 reply 1 retweet 0 likes -
OK I am surprised and intrigued, thanks! Against a truncated-DC-based distinguisher, or LC, or something else?
1 reply 0 retweets 0 likes -
https://gist.github.com/sneves/15d7ae82831044b0ac12c413adad36bf … (Note the mins) Didn't investigate further, we just moved on from that candidate.
2 replies 4 retweets 2 likes -
Replying to @sevenps @ciphergoth and
Each direction of diffusion of the differential is blocked by a 1. So try 2 rounds |, 2 rounds &.
3 replies 0 retweets 1 like -
-
-
Sorandsa20?
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.