I'm reading Mastring Bitcoin/ch05. In this chapter, it says "Because the extended key is 512 or 513 bits, it is also much longer than other Base58Check-encoded strings we have seen previously."
Why can an extended key be 513 bits long? I think it should be: pub/private-key(256bits) + chain-code(256bits) = 512bits.