@varx oh for sure, those are definitely risks. No way to really know though. I'll just design it the best way I can think of and hope for the best. I'm betting that sticking to really basic applications like authenticated encryption and signing will get me pretty far. I was doing pretty great until I tried to do anonymous multi-recipient encryption. Think I've about got it though.