Y
Hacker News
new
|
ask
|
show
|
jobs
by
tadfisher
735 days ago
Fair points. AES_GCM_SIV [1] is my choice where it's supported, personally, which is nonce-reuse-safe (wrt to key material leaks). Plus at least the primitive is hardware-accrlerated more often than not.
[1]
https://en.wikipedia.org/wiki/AES-GCM-SIV?wprov=sfla1