On 16 December 2015 at 14:01, Brian Smith <[email protected]> wrote: > Martin Thomson <[email protected]> wrote: > Why?
If there were a stupidly high limit, then I would argue for no rekeying facility. But the numbers Watson ran suggested that GCM starts to look shaky at 2^36. That's too low for some applications. For the rest of the argument I suggest you reread my last mail. _______________________________________________ TLS mailing list [email protected] https://www.ietf.org/mailman/listinfo/tls
