- 1
- 2
- 3
We could replace the nonce with a deterministic value, but it's not entirely clear what the cryptographic implications are. At the very least, it allows attackers to obverse that a secret has changed, or that it has changed back to a previously observed value.
https://github.com/edolstra/rfcs/blob/nix-encryption/rfcs/0005-nix-encryption.md