2 ms·
(beware, I'm a dog) Misusing those primitives can kill all guarantees, of course, the amount of kill dependent on the amount of misuse. Using non random keys
by eurg 6y ago
(beware, I'm a dog)
Misusing those primitives can kill all guarantees, of course, the amount of kill dependent on the amount of misuse. Using non random keys will kill even more.
It's about ease of correct implementation, use, and what kind of degradation happens if a side-channel leaks a specific item:
It seems that w/AES (within the AES-GCM construction) can leak a key that is useful against all other uses of the original AES key that was used to derive the authentication key.
ChaPoly uses a construction where all crypto operations for a message exchange use a key which if leaked, cannot be reused to attack so many other message exchanges as well, because it incorporates both main key and nonce in the derivation.
- api 6y agoAhh I see the difference... total forgery capability vs. forgery capability only with the same nonce (which can be detected).