Write a sketch of how a padding oracle attack would work against a CBC-encrypted message authenticated with truncated HMAC.
It's like a standard padding oracle attack, but 4 billion times slower (on average) and requires 4 billion times more CPU work and bandwidth, and you have to be able to distinguish between a HMAC failure and a padding error.