Jean-Luc Cooke wrote:
>Like you said, CBC is not trivial to temper with - though it is do able. CTR
>is trivial on the other hand. Which is why NIST and every cryptographer will
>recommend using a MAC with CTR. (Why still have CTR? Unlike CBC, you can
>compute the N+1-th block without needing to know the output from the N-th
>block, so there is the possibility for very high parallelizum).
I'm worried about the potential for confusion, so let me clarify: Good
cryptographers will recommend using a MAC, whether you use CTR, CBC,
or CFB. The need for a MAC is not specific to CTR; CBC is not exempt.