Since I'm on a roll with truncated hashes: SHA2-512/384, and SHA2-512/256 are not vulnerable to a Merkle-Damgard length extension attack.
Thus, a construct like hash(key + message) can be used similar to SHA3 [1]
Thus, a construct like hash(key + message) can be used similar to SHA3 [1]
No comments yet.