Explicit rejection was recommended by Sophie Schmieg at the end of <
https://keymaterial.net/2024/11/05/hashml-dsa-considered-harmful/>. According to
https://eprint.iacr.org/2022/365.pdf ("Failing gracefully: Decryption failures and the Fujisaki-Okamoto transform") by Kathrin Hövelmanns, Andreas Hülsing, and Christian Majenz, there is a security proof for explicit rejection in schemes that use the T-transform, like HQC does. Plaintext confirmation can only improve the situation.
Should HQC use explicit rejection instead of implicit rejection, or is the risk not worth it?
The following combination should provide the strongest binding properties:
1. Use explicit rejection instead of implicit rejection.
2. Use the seed as the private key format, with the expanded format only usable as a cache.
--
Sincerely,
Demi Marie Obenour (she/her/hers)