2017.06.14 22:57:38

Daniel J. Bernstein, replying to "Adam Langley (@agl__)":

NIST demanding 2^n preimage security for SHA3-n was always about optics (can't let SHA-2 sound better!), not any legitimate fear or caution.


Adam Langley (@agl__), replying to "Brian Smith (@BRIAN_____)":

I think the Wang attacks resulted in excessive fear and caution, making SHA-3 candidates excessively cautious.