Re: Are there problems with Merkle-Damgaard and SHA-256?
From: Francois Grieu (fgrieu_at_francenet.fr)
Date: Wed, 31 Aug 2005 08:07:48 +0200
In article <firstname.lastname@example.org>,
"D. J. Bernstein" <email@example.com> wrote:
> * SHA-256(m) takes two invocations of the compression function
> when m is short.
I checked again, and come to the conclusion that SHA-256(m)
takes ONE invocation of the compression function whem m is
less than 448 bits. Did I miss something?