• If I know the plaintext I can change CTR encrypted messages
  • e.g. If I know and I know , I can make a ciphertext that decrypts to any message I want, e.g.
  • New ciphertext is
  • Decrypt it