Hal Finney | 14 Sep 2005 05:32

Truncated tags

What if someone doesn't want to use a 128 bit authentication tag, but
perhaps a shorter one such as 64 bits.  Is it safe, with this kind of
MAC, to truncate the tag to a shorter size?  What kinds of security
issues arise?

Thanks -

Hal Finney


Gmane