It needs some basic security review, which I'll try do next week (check for security margin, optimality of rotation counts, etc.). But after a lot of experience with this kind of construction (BLAKE, SipHash, NORX), I'm confident it will be safe as it is. On Fri, Dec 16, 2016 at 1:44 PM Jason A. Donenfeld wrote: > Hey JP, > > On Fri, Dec 16, 2016 at 9:08 AM, Jean-Philippe Aumasson > wrote: > > Here's a tentative HalfSipHash: > > https://github.com/veorq/SipHash/blob/halfsiphash/halfsiphash.c > > > > Haven't computed the cycle count nor measured its speed. > > This is incredible. Really. Wow! > > I'll integrate this into my patchset and will write up some > documentation about when one should be used over the other. > > Thanks again. Quite exciting. > > Jason >