I believe we should add a note here explaining that a self-contained nonce (e.g., HMACed) is fine as well provided the underlying algorithm (e.g., HMAC) provides enough entropy. I believe that is also roughly what was discussed 1-2 weeks ago when this was discussed in the WG?
Originally posted by @c2bo in #722 (comment)
I believe we should add a note here explaining that a self-contained nonce (e.g., HMACed) is fine as well provided the underlying algorithm (e.g., HMAC) provides enough entropy. I believe that is also roughly what was discussed 1-2 weeks ago when this was discussed in the WG?
Originally posted by @c2bo in #722 (comment)