Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How difficult to find collisions in this poly1305 implementation? #8

Open
silviuk opened this issue Dec 6, 2022 · 0 comments
Open

Comments

@silviuk
Copy link

silviuk commented Dec 6, 2022

Hi, we played with poly1305-donna and we like that it's quite fast. We'd like and would like to ask how difficult it is, with this specific implementation, to cause a collision (e.g. generate a different message with the same MAC) for an attacker that would know the secret key passed to poly1305_auth()? Of course, we'd use a key only once per message.

Thank you and sorry for asking here, don't know where else.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant