Hacker Newsnew | past | comments | ask | show | jobs | submit | fedor_brunner's commentslogin

Adam Langley thinks that NIST continually pick algorithms that aren't suited to software implementations. https://www.imperialviolet.org/2012/10/21/nist.html

(In a NIST paper about the selection of AES they state: “table lookup: not vulnerable to timing attacks.” Oops. If you're building your own hardware, maybe.)


I would love to know your opinion about ARX ciphers.

Direct implementation of AES from specification can be attacked using cache-timing side-channel. ARX ciphers are much easier to implement in software and also because they run in constant time, and are therefore immune to timing attacks.

What is your opinion of ARX ciphers Chacha20 (from Daniel J. Bernstein ) and Threefish, Skein hash (Bruce Schneier, Niels Ferguson) ?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: