Comment by Sesse__

Comment by Sesse__ 17 hours ago

1 reply

The new one is randomly chosen (with the randomness coming from both parties, and then combined using ECDH and/or KEM). So you cannot predict it from previous key material, pretty much by definition.

immibis 16 hours ago

They also don't know the random elements used in previous headers, since they're thrown away a few rounds after the message was decrypted.