Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That last sentence is paraphrasing a recent djb cfrg post: http://www.ietf.org/mail-archive/web/cfrg/current/msg04880.h...


Unless I'm missing something, the point he's making about holding onto keys hasn't much to do with the algorithms you're using.


Correct, it's algorithm-agnostic. FWIW, Salsa20/12 is the officially-sanctioned eSTREAM winner; it's a perfectly fine cipher choice.


If you had to use Salsa20, could you foresee a design where you'd choose Salsa20/12?


Maybe in some high-throughput application, or something under hard performance constraints. IIRC VMWare uses Salsa20/12 for its remote desktop encryption thing.

20 rounds gives a more comfortable security margin, though, so it's a default that lets you sleep well at night. That said, an attack that convincingly broke 12 rounds could be enough to start thinking of switching to something else.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: