Re: [Cryptography] Shortening block cipher length...

Adam P. Goucher wrote on 7/18/21 6:01 AM:
E = AES(P XOR ChaCha20(Ctr))

I suppose we could be silly and say that even that construction "exposes" with repeated cipher text blocks if the plain text blocks happen to equal ChaCha20(Ctr), but that is highly improbable and who would care anyway.

The other example with P going up and down in concert with Ctr also seems improbable, but decidedly less so.

-- Patrick
