@wolf480pl@mstdn.io @lynne@pars.ee It's got to do with the sponge construction as far I'm aware, because there's hidden state and how it's updated depends both on the inputs and the state.
Though probably you'd want to use some kind of KDF for this anyways, SHA3 has a KDF mode that's faster than just using in HKDF
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Ignas Kiela (ignaloidas@not.acu.lt)'s status on Wednesday, 26-Mar-2025 20:44:17 JST Ignas Kiela