On Fri, Dec 2, 2022, at 12:55, Martin Duke wrote: > I got a little grief in the sec AD review about not using a KDF for all > the random values, so I might as well do that.
I would have no problem if you chose to ignore that as the misapplication of an otherwise useful principle that is - apparently - now misunderstood.
