Posted by Nahuel GrisolÃa on Oct 30
Hi! I believe that what you’re saying in number 2 is not completely true.
I agree that an hmac is safer. Correct me if I’m wrong but $secret should
be at the beginning of the string in order to run a lenth extension attack.
Cheers,
Nahu.-