argumentcomputer/neptune

MDS matrix security

Closed this issue · 1 comments

The recent update of the Poseidon article drops in additional requirements on the MDS matrix security, see p. 7. Any idea if a randomly sampled Cauchy matrix over a large field is still safe?

Our auditors (one of whom is a Poseidon author) have confirmed that the new requirements do not affect our implementation, and our MDS matrixes remain secure. More generally, they have confirmed that none of the updates in the paper affect our implementation — so their previous analysis that our implementation is correct, secure, and in agreement with the paper holds also for the updated paper.