2018.11.01 01:28:37 (1057791485016526848) from Daniel J. Bernstein:
Wow: Inoue and Minematsu announce a fast attack breaking OCB2. https://eprint.iacr.org/2018/1040 OCB2 appeared at Asiacrypt 2004; advertised provable security; is a current ISO standard. OCB3 seems safe, and Rogaway has been recommending OCB3 for years, but the OCB2 story is terrifying.