Tight Security of TNT Reinforcing Khairallah’s Birthday-bound Attack

. In a recent paper, Khairallah demonstrated a birthday-bound attack on TNT , thereby invalidating its (beyond-the-birthday-bound) CCA security claims. In this short note, we reestablish a birthday-bound CCA security bound for TNT . Furthermore, using a minor variant of Khairallah’s attack, we show that our security bound is tight. We provide a rigorous and complete attack advantage calculations to further enhance the confidence in Khairallah’s proposed attack strategy.