|
|
|
|
|
by tptacek
617 days ago
|
|
The GCM IV thing didn't ring true to me either; in fact, the whole reason we have XAES-type constructions is to enable fully nondeterministic IVs, which don't fit comfortably in the GCM IV space. Regarding padding oracles: it is most definitely not necessary for a target to generate a "padding error", or even an explicit error of any sort, to enable the attack. |
|
I would be happier if there were fewer vague assertions in these sorts of writeups...