@danmcd @letoams @mattblaze @marabou Btw: while I was working on IPsec I also wrote one of my favorite papers: Probable Plaintext Cryptanalysis, https://www.cs.columbia.edu/~smb/papers/probtxt.pdf. (Some folks at AT&T wondered if we should patent it. I pointed out that a) the NSA would be the major user, and we'd never know if they infringed or indeed if they already had it, and b) much of the concept, especially the two-packet variant, was likely anticipated by the attacks on Enigma…)