That's a very good question. I heard it from Nate Lawson, and this would have been right around the time I wrote the [A-E-S "doing it wrong"] (just Google that) blog post. It's bugged me for years, too. I pretty sure he didn't make it up!
The big shift I perceived from him was from generic composition of authenticators and ciphers and such, and long sprawling discussions about E-t-M and M-t-E and "the Horton Principle" and stuff, to the AEAD ciphers pretty much everybody uses now.
Comments
That's a very good question. I heard it from Nate Lawson, and this would have been right around the time I wrote the [A-E-S "doing it wrong"] (just Google that) blog post. It's bugged me for years, too. I pretty sure he didn't make it up!
The big shift I perceived from him was from generic composition of authenticators and ciphers and such, and long sprawling discussions about E-t-M and M-t-E and "the Horton Principle" and stuff, to the AEAD ciphers pretty much everybody uses now.