XChaCha20-Poly1305 is for the case where you don't have a way to guarantee a unique nonce. How would you choose one?
If you feed random+message+time+counter+unique into PRNG state then you can just use the PRNG, right? Though message is low entropy.
-
-
I dunno — I don't really like the paradigm of stateful PRNGs that much…
-
Consider a message with the same value always sent at the same time. Then message + time would be perfectly correlated.
-
Stateful PRNGs seem like they can mitigate this kind of correlation, esp. when attacker can't see all requests/responses.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
