If you read anything, from BitLocker reversing tool source to articles to FIPS reports, it says it uses AES-CCM to wrap keys. It doesn't. It uses AES-CTR. Somehow everyone has managed to write AES-CTR implementations and call them AES-CCM. WTF.
-
Show this thread
-
The only thing "CCM" about it is that it prepends (15 - nonce_len - 1) (so 0x02) to nonces. It doesn't use a MAC. It doesn't have associated data. And crucially, it doesn't use the first keystream block for that, which definitely makes it not CCM and not compatible with CCM.
3 replies 2 retweets 10 likesShow this thread -
Replying to @marcan42
there's no mention of ccm anywhere in group policies thopic.twitter.com/OCyAiMfmLG
1 reply 0 retweets 0 likes
Replying to @13xforever
Those are the disk encryption algorithms. "CCM-not-really" is used for key wrapping.
8:52 AM - 3 Jan 2019
0 replies
0 retweets
3 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.