https://vxtwitter.com/jedisct1/status/1761792488572866928

We show that for many truncated tag sizes; the security levels are far below, not only the current NIST requirement of 112-bit security, but also the old NIST requirement of 80-bit security. We therefore strongly recommend NIST to revise SP 800-38D.
 
 
Back to Top