As Joe notes, we assume a fixed length. The definitions in the IETF all
use N_MIN = N_MAX = 12, but the NIST publications often veer into all
sorts of wild fantasies of arbitrary nonce length. This rarely works
well, as we see from the analysis in 2018/993.
As Joe notes, we assume a fixed length. The definitions in the IETF all use N_MIN = N_MAX = 12, but the NIST publications often veer into all sorts of wild fantasies of arbitrary nonce length. This rarely works well, as we see from the analysis in 2018/993.
Closes #41.