3 ms·
HT to Filippo (https://twitter.com/FiloSottile/status/1260598284395126786 https://twitter.com/FiloSottile/status/1260598284395126786). Another submission 10 ho
by eurg 6y ago
HT to Filippo (https://twitter.com/FiloSottile/status/1260598284395126786 https://twitter.com/FiloSottile/status/1260598284395126786). Another submission 10 hours ago didn't catch (https://news.ycombinator.com/item?id=23165258 https://news.ycombinator.com/item?id=23165258).
Too bad, because the blog post illustrates some limitations with the construction that are interesting to know, like the problem with using the same authentication key for every key instead of key/nonce pair, or the fact that AES-GCM is not "message committing" - a TIL for me.
It's also very pragmatic in the end: "Don’t throw AES-GCM out just because of my opinions. It’s very likely the best option you have."