Yeah I think we incorrectly assumed that GMAC offers preimage resistance when the key is known. You’re right, that text is wrong. Luckily it doesn’t impact the protocol guarantees, since QUIC isn’t resilient to active attackers causing handshakes to fail
4 months ago
2
0
0
0