On Wed, Sep 3, 2025, at 03:12, Tim Hollebeek wrote: > In particular, X-ECB is horribly broken and these days probably should > not be used by anyone, ever. That advice is already a decade old or > more, at this point.
Total distraction, but RFC 9001 uses ECB. Defensibly so, I believe. Though perhaps you might consider the use as part of a more advanced mode, HN-1. Now for the tongue-in-cheek version: Absolute statements are always wrong. _______________________________________________ TLS mailing list -- tls@ietf.org To unsubscribe send an email to tls-le...@ietf.org