Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you had to use Salsa20, could you foresee a design where you'd choose Salsa20/12?


Maybe in some high-throughput application, or something under hard performance constraints. IIRC VMWare uses Salsa20/12 for its remote desktop encryption thing.

20 rounds gives a more comfortable security margin, though, so it's a default that lets you sleep well at night. That said, an attack that convincingly broke 12 rounds could be enough to start thinking of switching to something else.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: