[openpgp] Re: PQC composite sig context string? [was: Re: Re: AD review of draft-ietf-openpgp-pqc-12]
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 29/09/2025 16:06, Falko Strenzke wrote: > My conclusion from this is that protocols should generally start signed > data with a long enough magic constant, as this makes crafting such > cross-protocol aliases much less feasible. How long is "long enough"? Is it sufficient to use a magic number that is in common use and/or non-colliding? Or would we need to use a minimum bit length of magic to also make hash collisions infeasible? If we used both a magic number and a random salt, would the security properties be combined, or would they interfere? A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]