-------------------------------------------------------------------------- From: Andreas Westfeld Date: Wed, 4 Jan, 2023 17:56 To: crypto-competitions at list cr yp to -------------------------------------------------------------------------- * PGP - S/MIME Signed Dear Keccak Team, the messages 00 00 00 00 00 00 and 8B collide over rounds 3 and 4. The collision was obtained by looking sharply. (For zero input state, only the round constant matters. There is a zero round constant for i_r = 3 and b = 200. The round constant for i_r = 4 is 0x8b, which can be reproduced by another message in one block.) counter += verifyCollisionChallenge( // Keccak[r=40, c=160, rounds=2]: collision challenge 40, 160, 2, 3, // fill in this line with the start round index (0=first) (const UINT8*)"\0\0\0\0\0\0", 48, // fill in this line (const UINT8*)"\x8B", 8 // and this line with a different input ); Best regards, Andreas Westfeld (HTW Dresden, Faculty of Informatics/Mathematics, Germany) * Andreas Westfeld * Issuer: Verein zur Foerderung eines Deutschen Forschungsnetzes e. V.