2017.06.14 22:37:42 (875089888416288770) from Daniel J. Bernstein, replying to "Brian Smith (@BRIAN_____)" (875071469511778304):

NIST demanded 2^256 preimage security for SHA3-256 through the whole competition, then suddenly proposed dropping to 2^128 for 1.2x speedup.

The current dispute between @agl__ and @keccakteam is about a much bigger SHA-3 speedup, namely vectorization, which NIST SP 800-185 allows.

NIST SP 800-185 vectorizes not by changing the security level but by changing the order of processing input blocks. Breaks interoperability.

Now @agl__ correctly observes that this fast (vectorized) function isn't SHA-3, while @keccakteam correctly observes that it's standardized.