If I understand, proposal 295 looks similar to either BEAR or LION from the LIONNESS. I vaguely recall both BEAR and LION being "broken" in some setting, although I cannot site the paper. Anyone?
I suppose the BEAR and LION break originates from using them for authentication while proposal 295’s separate SVer function fixes this?
Jeff