|
|
|
|
|
by pbsd
4256 days ago
|
|
I'm not sure what's your point. Your claim was that constant-time was not a big issue for many people. Maybe it's not. But the Groestl people wrote an entire report on implementation strategies for it [1], specifically mentioning cache-timing issues on the table-based approaches. They clearly took it seriously. There are many competing requirements when designing a primitive. Groestl's choices were not necessarily wrong, even when treating side-channel attacks as a "big issue". I don't like Groestl, but I get what they were trying to achieve; Keccak did it much better, though. [1] http://www.groestl.info/groestl-implementation-guide.pdf |
|
I will admit they are less at fault than the CAESAR candidates who insist on re-using AES.