Skip to content

SHA3-10 Security, zeroization, and API misuse docs #45

Description

@turkananation

SHA3-10 Security, Zeroization, and API Misuse Docs

Summary

Document SHA-3/SP 800-185 security boundaries, zeroization limits, KMAC misuse
guidance, and claim wording.

Scope

  • Add KMAC key length guidance.
  • Add KMAC output/tag length guidance.
  • Document byte-only public API limitations if applicable.
  • Document no hard constant-time or hard memory-erasure guarantee for Dart.
  • Update SECURITY_AUDIT.md, FIPS_COMPLIANCE.md, and README wording.

Acceptance criteria

  • Public docs distinguish algorithm/vector evidence from CMVP/FIPS 140.
  • KMAC is not described as HMAC.
  • TupleHash and ParallelHash use cases are documented without overclaiming.

References

  • doc/FIPS202_SP800185_RELEASE_GUIDE.md - Security and Side-Channel Posture
  • doc/FIPS_140_BOUNDARY.md
  • SP 800-185 Section 8

Priority: P1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1Priority: highSHA3FIPS 202 and SP 800-185 SHA-3 workenhancementNew feature or request

    Projects

    • Status
      Backlog

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions