Hacker News new | ask | show | jobs
by CiPHPerCoder 3725 days ago
The problem isn't IGE. It's that they're using SHA1 (not HMAC-SHA1) in a "MAC and Encrypt" construction.