If you don’t care about a built in MAC, would you recommend CTR? OCB?
If you don’t care about a built in MAC, would you recommend CTR? OCB?
The user wants something that works reliably. If it's hard to implement, confidence decreases. You can compensate with external audits, but those are expensive.
> If you don’t care about a built in MAC, would you recommend CTR? OCB?
You almost always care about built in MAC. If you don't authenticate your data, you will most likely run into trouble. And if you really don't care, I'd rather sidestep the CTR vs OCB vs WTF entirely by using Chacha20 (fast without dedicated hardware, naturally immune to timing attacks, dead simple to implement).
(In the general case, I'd recommend Chacha20 + Poly1305 constructions.)
If you don't have any very good reasons to use CTR (encrypting lots of data with the same key) you.probably shouldn't.