3 ms·
Better, but still slightly wrong. You really want to encrypt, then MAC the ciphertext. Then, before decrypting, check that MAC and don't act at all if it is inv
by AnIrishDuck 13y ago
Better, but still slightly wrong. You really want to encrypt, then MAC the ciphertext. Then, before decrypting, check that MAC and don't act at all if it is invalid [1].
1. http://crypto.stackexchange.com/questions/202/should-we-mac-then-encrypt-or-encrypt-then-mac http://crypto.stackexchange.com/questions/202/should-we-mac-...