Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As I remember it, the balance of the bytes in the AES block are used for the counter. At any rate, the convention is essentially universal.


Sounds above my (current) head.

Here I thought GCM was some modern foolproof/footgunless design.


It is sort of infamously footgunny.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: