Skip to main content

Did I just make the first fully correct Ascon implementation?

0
Medium
Published: 10/03/2026 (10/03/2026, 10:31:12 UTC)
Source: Reddit Cybersecurity

Description

This content discusses a user-developed implementation of the Ascon lightweight cryptography algorithm, which is the NIST-selected standard for constrained environments. The user created a library and demo tools to provide a more general-purpose and spec-compliant Ascon implementation than the original reference code. The post is informational and does not report any vulnerability or exploit. NIST finalized Ascon as a standard in August 2025 with no known security issues reported here.

Reddit Discussion

r/cybersecurity·posted by u/internet_safari_
00

Months ago I was reading about and learning ciphers for a notes app of mine launching whenever I get approved for Google Play, iOS app store, and F-Droid. I read about the various competitions and came across the latest winning NIST cipher: "Lightweight Cryptography" NIST Lightweight Cryptography. The winner was the Ascon cipher and the four agreed upon implementation ciphers, which you can read about here.

I found their reference implementation called ascon-c on GitHub and made a couple CLI tools from those files. But I had to stitch together and modify the files from various folders. The ascon-c repo contained files primarily for building their demo app, not a general purpose library for use in other projects. So out I went looking through the paper and their code to build a library that actually works like a library.

Then another problem: the paper has a max customization string for cxof, ascon-c does not, it will take any. A while later I finish what I feel is the best and most true to spec Ascon library, you may check out here:

https://github.com/Iain-Donald/ascon-lib

I tried to add instructions for ease of use and a demo app. If anything is confusing please tell me. I hope it works without issue from beginners to use in larger projects.

And a bonus GUI demo you may use if you have Linux, but it should compile on FreeBSD, maybe MacOS and Windows and anything with Tcl/Tk. Found here:

https://github.com/Iain-Donald/sable

Enjoy!

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 10:46:05 UTC

Technical Analysis

The post describes an individual's effort to build a fully correct and usable implementation of the Ascon lightweight cryptography algorithms standardized by NIST in SP 800-232. The Ascon family includes AEAD, hash, XOF, and customized XOF functions designed for constrained devices. The user improved upon the reference implementation by addressing limitations such as customization string handling and packaging the code as a reusable library. This is a community contribution and not a report of a security flaw or exploit.

Potential Impact

There is no indication of any security vulnerability or exploit in the Ascon implementations discussed. The content does not describe any impact to confidentiality, integrity, or availability. It is an informational post about a cryptographic implementation effort.

Defensive Guidance

No mitigation or patching is required as this is not a vulnerability or threat. Users interested in Ascon implementations can consider this library as an alternative to the reference code, but should independently verify correctness and security for their use cases.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6ac0dce9a43b0b3b89ba088b

Added to database: 10/03/2026, 10:46:01 UTC

Last enriched: 10/03/2026, 10:46:05 UTC

Last updated: 10/04/2026, 03:46:05 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses