@bascule @matthew_d_green @tqbf @dchest Usually key is first and include the nonce length. HMAC(K_mac, nonce_length || nonce || ciphertext)
@marshray do you think there's a non-negligible chance of that happening given a 128-bit key and 128-bit nonce?
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.