-// MACKey = XSalsa20(authKey, nonce, 0x00...)
-// nonce = prefix || byte-num || bit-val
-// bit-val = (0x00|0x01) || 0x00... || bit sequence number
-//
-// 64-bit prefix is explicitly provided during the chaffing. byte-num is
-// big-endian 64-bit byte's sequence number. So 24-bit nonces for
-// XSalsa20 will be the following:
-//
-// prefix || 0x0000000000000000 || 0x0000000000000000
-// prefix || 0x0000000000000000 || 0x0100000000000000
-// prefix || 0x0000000000000000 || 0x0000000000000001
-// prefix || 0x0000000000000000 || 0x0100000000000001
-// prefix || 0x0000000000000000 || 0x0000000000000002
-// prefix || 0x0000000000000000 || 0x0100000000000002
-// ...
-// prefix || 0x0000000000000001 || 0x0000000000000000
-// prefix || 0x0000000000000001 || 0x0100000000000000
+// MACKey1, MACKey2, ... = XSalsa20(authKey, nonce, 0x00...)
+// nonce = prefix || 0x00... || big endian byte number