Poly1305 is designed to ensure that forged messages are reject= ed with

a probability of 1-(n/2^107), where n is the maximum length of= the

input to Poly1305. In the case of (D)TLS, this means a m= aximum

forgery probability of about 1 in 2^93.

Corrected Text

Poly1305 is designed to ensure that forged messages are reject= ed with

a probability of 1-(n/2^106), where n is the maximum length of= the

input to Poly1305. In the case of (D)TLS, this means a m= aximum

forgery probability of about 1 in 2^92.

If we are in the situation C =3D 0, D =3D 1 and L=3D=
2^{14} for (D)TLS, the forgery probability may indeed not be affected (and =
may even be smaller). However, the explanation "Poly1305 is designed to ens=
ure that forged messages are rejected with a probability of 1-(n/2^107), wh=
ere n is the maximum length of the input to Poly1305." is presenting Poly13=
05 as slightly stronger than it really is (and there is an attack with succ=
ess probability 2^{-106} with C=3D1, D=3D1, L=3D1, as the hashing key r has=
106 effective bits).

Regards,

Xavier