Zoltan Fridrich <[email protected]> writes: >> Do you think it would be reasonable to drop the sha2 variants in the >> first iteration? > > Yes, I think its fine to just have shake variants in the first iteration.
I'm leaning towards starting with slh_dsa_shake_128s based on my rather minimal code (about 1000 lines, including comments), and iterate from there. Regards, /Niels -- Niels Möller. PGP key CB4962D070D77D7FCB8BA36271D8F1FF368C6677. Internet email is subject to wholesale government surveillance. _______________________________________________ nettle-bugs mailing list -- [email protected] To unsubscribe send an email to [email protected]
