Re: End of WG Last Call for AH+MD5 and ESP+DES+3DES

I think that MD5(key, text, key) may be more secure than the double hash.
My understanding is that Kaliski's suggestion was based on the idea
that MD5(text) might be a useful subfunction.  However, I'm uneasy at
the idea of a possible cryptanalysis of MD5(foo,key); not a question I've
seen examined before.