- encoding on group elements where all encodings have the same length.
-\item $\id{enc-ge-hash}$ and $\id{dec-ge-hash}$ together define an
- encoding on group elements where all encodings should have the same length.
+ encoding on group elements where all encodings have the same length, except
+ with negligible probability.
+\item $\id{enc-ge-hash}$ and $\id{dec-ge-hash}$ together define an encoding
+ on group elements where all encodings \emph{should} have the same length,
+ except with negligible probability.\footnote{%
+ The existence of groups without (mostly) fixed-length hashing encodings
+ is a historical mistake. If a variable-length encoding is used here,
+ information about group element(s) being hashed may leak to an adversary
+ through timing channels.} %
+ The decoding operation is never invoked, so it need not be possible to
+ implement it efficiently, though it must be theoretically possible to
+ decode encodings unambiguously.