Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I read the post, it doesn't answer the question other than there are too many existing standards/we don't like them, let's create another one https://xkcd.com/927/

Replacing working cryptographic standards is expected from an NSA front.



From the Cloudflare article:

> A paper by Martinez et al. provides a thorough and technical comparison of these different standards. The key points are that all these existing schemes have shortcomings. They either rely on outdated or not-commonly-used primitives such as RIPEMD and CMAC-AES, lack accommodations for moving to modern primitives (e.g., AEAD algorithms), lack proofs of IND-CCA2 security, or, importantly, fail to provide test vectors and interoperable implementations

For more thorough analysis of one of its novelties namely authenticated mode you can check this paper:

Analysing the HPKE Standard:

https://link.springer.com/chapter/10.1007/978-3-030-77870-5_...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: