On 16 December 2015 at 14:01, Brian Smith <[email protected]> wrote:
> Martin Thomson <[email protected]> wrote:
> Why?

If there were a stupidly high limit, then I would argue for no
rekeying facility.

But the numbers Watson ran suggested that GCM starts to look shaky at
2^36.  That's too low for some applications.

For the rest of the argument I suggest you reread my last mail.

_______________________________________________
TLS mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/tls

Reply via email to