Zoltan Fridrich <[email protected]> writes:

>> Do you think it would be reasonable to drop the sha2 variants in the
>> first iteration?
>
> Yes, I think its fine to just have shake variants in the first iteration.

I'm leaning towards starting with slh_dsa_shake_128s based on my rather
minimal code (about 1000 lines, including comments), and iterate from there.

Regards,
/Niels

-- 
Niels Möller. PGP key CB4962D070D77D7FCB8BA36271D8F1FF368C6677.
Internet email is subject to wholesale government surveillance.
_______________________________________________
nettle-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to