6 votes

Understanding extended-nonce constructions: How and why XSalsa20/XChaCha were designed, and why they’re secure