Hi Milan, Thank you for taking the time to provide these detailed clarifications.
> An attacker model that can record all writes can easily replays individual > sectors, > including auth tags. It is just not secure in this scenario. Understood. Our review also found that the current setup does not provide sufficient protection against an attacker under this threat model. > If you want to help, then please focus on promoting better AEAD modes > (we have AEGIS in kernel, for example). That is a fair point. We appreciate the suggestion and will look more closely at AEGIS and its existing kernel support. Thank you again for your feedback and guidance. Kind regards, Shukai Ni and Jo Van Bulck DistriNet, KU Leuven
