2 @section GOST 28147-89 cipher modes of operation
6 Encryption and authentication modes
7 @item What modes are defined
15 @url{https://tools.ietf.org/html/rfc5830.html, 5830}
20 @item 28147-89 MAC is completely unusable:
22 @item Reduced 16-round Magma cipher is used instead of 32 one.
23 @item Authenticating data does not have neither padding, nor
24 length specifying, so @code{MAC(0xDEAD) = MAC(0xDEAD00)}.
26 @item Specified counter (CTR) mode increments counters with predefined
27 constants for 32-bit halves of the block. This differs from simpler
28 counter mode implementations.