[mosh-devel] Block cipher's mode of operation

Nicolas Braud-Santoni nicolas at braud-santoni.eu
Tue Sep 18 15:03:08 EDT 2012


I noticed that neither the USENIX paper nor the website motivates the
choice of OCB as an authenticated mode of operation.
More specifically, why OCB, a patent-encumbered mode (although with an
exception for GPL code), was chosen over GCM, which is significantly
faster, non-patented, and has similar security guarantees ?


More information about the mosh-devel mailing list