2016.05.23 22:35:02 from Daniel J. Bernstein:

Each direction of diffusion of the differential is blocked by a 1. So try 2 rounds |, 2 rounds &.


2016.05.23 20:25:08 from Paul Crowley:

Not knocking NORX, which is very cool! But I wouldn't use its H-op to build a Chor-Chor.

2016.05.23 20:54:52 from Samuel Neves:

"Sorsa" was one of our first choices. Even after 20 rounds, it is easily distinguishable from random.

2016.05.23 21:12:14 from Paul Crowley:

OK I am surprised and intrigued, thanks! Against a truncated-DC-based distinguisher, or LC, or something else?

2016.05.23 21:42:12 from Samuel Neves: (Note the mins) Didn't investigate further, we just moved on from that candidate.