This is an old revision of the document!

The Algorithm

  • Author(s): Watson Ladd
  • CAESAR submission: McMambo


Samuel Neves points out in this thread a high-probability differential for the block cipher underlying McMambo. The designer acknowledges this as a forgery attack with success probability 2^{-24}, thus calling McMambo “dead”.

Last modified: 21/03/2014 08:06:29