[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: Calling the question: derived vs. explicit IV
Add me to the list of people supporting an explicit IV only.
I agree with Mr. Rogers' comment that we shouldn't mandate what is in the IV.
The two drafts I wrote, and I believe Roy's as well, suggest using the last block of the
previous encryption pass. This is cheap and common. I only suggested that people
use a pseudo-random value for the first pass...
Ed said it best when he stated that he'd like to see ship what we've been testing for
quite some time now. I do not believe we are "changing to" an explicit IV. I believe,
if there is a change, it would be to derived IV. So I vote for sticking with explicit IV's.
-Rob