Hacker News new | ask | show | jobs
by ebiggers 2866 days ago
You can read about some of the other options considered here: https://marc.info/?l=linux-crypto-vger&m=152573520705012. But in the end, a new ChaCha-based mode suitable for disk encryption (https://eprint.iacr.org/2018/720.pdf) had to be designed since there didn't seem to be any alternative block cipher that met the strict performance and security requirements. LEA-128 maybe comes close, but it hasn't undergone too much cryptanalysis yet (much less than Speck).