4 ms·
I'm very happy to see djb's crypto work being supported in openssh! Does anyone know offhand why ChaCha was chosen instead of XSalsa20, which is used in NaCl?
by mct 13y ago
I'm very happy to see djb's crypto work being supported in openssh!
Does anyone know offhand why ChaCha was chosen instead of XSalsa20, which is used in NaCl?
- fefe 13y ago"ChaCha" family of ciphers aim to increase the diffusion per round while achieving the same or slightly better performance.The Aumasson et al. paper also attacks ChaCha, achieving one round less: ChaCha6 with complexity 2^140 and ChaCha7 with complexity 2^231 https://en.wikipedia.org/wiki/ChaCha20 https://en.wikipedia.org/wiki/ChaCha20 Also used in: https://tools.ietf.org/id/draft-agl-tls-chacha20poly1305-04.html https://tools.ietf.org/id/draft-agl-tls-chacha20poly1305-04....
- arnehormann 13y agoChaCha is a little faster and apparently a little more secure. Dig through http://www.ietf.org/mail-archive/web/tls/current/msg10843.html http://www.ietf.org/mail-archive/web/tls/current/msg10843.ht... for reference. EDIT found a better one: http://www.ietf.org/mail-archive/web/tls/current/msg10630.html http://www.ietf.org/mail-archive/web/tls/current/msg10630.ht...