On Thu, May 30, 2019 at 05:04:51PM +0200, Ard Biesheuvel wrote: > > But given your remark regarding CBC being the only algo that has this > requirement, I wonder if this might be sufficient as well. It's not that CBC is the only one with the requirement. It's just that this is the wrong output IV for CTR. Cheers, -- Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt