Skip to content

Support for xchacha in reverse mode #759

Answered by rfjakob
nullmonk asked this question in Q&A
Discussion options

You must be logged in to vote

No, unfortunately, this is insecure. Reverse mode needs a chipher that is resistant against nonce reuse, and (x)chacha-poly is not ( https://crypto.stackexchange.com/questions/32075/what-happens-if-a-nonce-is-reused-in-chacha20-poly1305 )

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by rfjakob
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #758 on June 21, 2023 18:15.