1

HMAC seems a bit complicated. Why can't we use $H(m||k)$ as a MAC? Unlike $H(k||m)$, length extension attacks won't work.

Is there some other obvious attack?

ithisa
  • 1,111
  • 1
  • 10
  • 23

0 Answers0