<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Disqus - Latest Comments for lazappa</title><link>http://disqus.com/by/lazappa/</link><description></description><atom:link href="http://disqus.com/lazappa/comments.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Thu, 10 Sep 2009 12:29:16 -0000</lastBuildDate><item><title>Re: Cryptographic Right Answers</title><link>http://www.daemonology.net/blog/2009-06-11-cryptographic-right-answers.html#comment-16310349</link><description>&lt;p&gt;Thanks for the reply. I just re-read the section that had me worried more carefully and it is indicating that reusing the same counter block with a secret key compromises that secret key, as you mention. The document starts calling the combination of the counter and the secret key a key stream in section 7 (Security Considerations). I was confusing key stream with secret key since the distinction in the RFC is subtle.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">lazappa</dc:creator><pubDate>Thu, 10 Sep 2009 12:29:16 -0000</pubDate></item><item><title>Re: Cryptographic Right Answers</title><link>http://www.daemonology.net/blog/2009-06-11-cryptographic-right-answers.html#comment-16301618</link><description>&lt;p&gt;I came upon this post at an opportune time while working on some new cryptographic features at my workplace. This prompted me to learn a bit more about the specifics of the recommendations made here. Not being familiar with CTR mode, I went and read over RFC 3686 which describes a similar approach to your recommendation. A major thing that it recommends that isn't mentioned here is that CTR is not appropriate for using with static keys. I haven't taken the time yet to fully digest why, but that seems like a big caveat to keep in mind.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">lazappa</dc:creator><pubDate>Thu, 10 Sep 2009 09:33:02 -0000</pubDate></item></channel></rss>