On Wed, Oct 19, 2011 at 08:09:17PM -0400, Nick Mathewson wrote: > Note that this design does not require that our stream cipher > operations be transitive, even though they are. Did you mean "commutative"? - Ian