4 ms·
https://www.imperialviolet.org/2014/06/27/streamingencryption.html https://www.imperialviolet.org/2014/06/27/streamingencryptio... Thomas's answer probably has
by paragon_init 11y ago
https://www.imperialviolet.org/2014/06/27/streamingencryption.html https://www.imperialviolet.org/2014/06/27/streamingencryptio...
Thomas's answer probably has to do with the risks of decrypting a stream and being unable to authenticate it first. (See also: the Cryptographic Doom Principle.)
- wolf550e 11y agoBut it is still safe to do random access AES-CTR if you've already checked the MAC. Random access is not a problem, decrypting before authenticating is a problem.
- paragon_init 11y agoI think that's why the statement was "be careful with" rather than "don't"