The only thing "CCM" about it is that it prepends (15 - nonce_len - 1) (so 0x02) to nonces. It doesn't use a MAC. It doesn't have associated data. And crucially, it doesn't use the first keystream block for that, which definitely makes it not CCM and not compatible with CCM.
-
-
Show this thread
-
Lol, I take that back. It *is* CCM, it's just that libbde incorrectly implements it as CTR and it works by accident (and returns 16 bytes of garbage before the plaintext). The correct ciphertext format is <12b nonce><16b tag><ciphertext>, not <12b nonce><ciphertext>.
Show this thread
End of conversation
New conversation -
-
-
What do you think, have Bitlocker a Backdoor?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
I wonder why they don't use XTS, which should be a better fit for block-based storage.
-
Key words: **wrap keys**. I didn't say anything about the sectors. They use AES-CBC or (in Windows 10) AES-XTS as an option.
End of conversation
New conversation -
-
-
Brings me back to the point i came to realize civilians will never know reliable security. Any such efforts will result in substantial countering efforts.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.