[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: Calling the question: derived vs. explicit IV



Add me to the list of people supporting an explicit IV only. 

I agree with Mr. Rogers' comment that we shouldn't mandate what is in the IV.
The two drafts I wrote, and I believe Roy's as well, suggest using the last block of the 
previous encryption pass.  This is cheap and common.  I only suggested that people 
use a pseudo-random value for the first pass...

Ed said it best when he stated that he'd like to see ship what we've been testing for 
quite some time now.  I do not believe we are "changing to" an explicit IV.  I believe, 
if there is a change, it would be to derived IV.    So I vote for sticking with explicit IV's. 

-Rob