> > My post provided a concrete example. I'd be happy to answer any > questions about it, but otherwise I'm not sure how to make it more > clear.
My apologies, I didn't read it carefully. You are absolutely right. Our scheme doesn't protect against the scenario. > Quite the opposite-- a large block cipher is a standard > construction I'm happy to hear it. Nevertheless, I didn't find any standartisation or implementation of the CMC mode (excluding the paper). Do you have some experience with other modes (such as HCTR, HEH)? _______________________________________________ bitcoin-dev mailing list bitcoin-dev@lists.linuxfoundation.org https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev