Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That is a good principle, but the context here is different.

FDE doesn't have space for and can't afford (because of the random read patterns) authentication tags, so it uses modes like AES-XTS instead.

What that HMAC does is just confirming that the passphrase is the right one. Think of it as a checksum, not as authentication.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: