4 ms·
From what I shallowly researched; GCM's nonce seems limited to 12 bytes by convention only. That nonce reuse is so fatal seems absurd to me. Would "salting" th
by majou 4y ago
From what I shallowly researched; GCM's nonce seems limited to 12 bytes by convention only. That nonce reuse is so fatal seems absurd to me.
Would "salting" the key safely tackle the problem?
Put explicitly;
send <- nonce || salt || ciphertext
recv -> decrypt(ciphertext, nonce, pbkdf(pass) || salt)
[edit: apply salt outside of the kdf]
- tptacek 4y agoAs I remember it, the balance of the bytes in the AES block are used for the counter. At any rate, the convention is essentially universal.