HKDF has poorly-understood subtleties. Let’s explore them in detail. NIST opened public comments on SP 800-108 Rev. 1 (the NIST recommendations for Key Derivation Functions) last month. The main thing that’s changed from the original document published in 2009 is the inclusion of the Keccak-based KMAC alongside the incumbent algorithms. One of the recommendations of SP 800-108 is called “KDF in Co