All Questions
Tagged with sigma-protocol 2nd-preimage-resistance
1 question
4
votes
1
answer
155
views
Security impact of weakened collision resistance for 128-bit Fiat-Shamir challenges
As I understand, to achieve a security level of $\lambda$, a hash function's output should be at least $2\lambda$ in length, since the search space is halved for collision resistance.
However, I am ...