Scott G. Kelly wrote: >Well, maybe I'm misunderstanding, but I have the impression that the >general thrust of this thread has been to *replace* AES-CBC with >AES-CTR. That was never my suggestion; at least, I would not suggest any such change to the standard. If someone else wants to propose it, I leave it to them to justify such a change to the standard.