On Mon, Apr 23, 2007 at 07:59:15PM +0900, Hironobu SUZUKI wrote: > > Hi, > > > That's right, hence the hashing and discarding the first 256 bytes > > from the keystream, as described in my previous post. > > I really appreciate if I could read a paper(s) about analysis of this > technique. http://eprint.iacr.org/2002/067 actually argues for 512 bytes. David