Skip to main content

9.7.6. Hiding Plaintext Length

9.7.6. Hiding Plaintext Length

AEAD ciphertexts produced by HPKE do not hide the plaintext length. Applications requiring this level of privacy should use a suitable padding mechanism. See [TLS-ECH] and [RFC8467] for examples of protocol-specific padding policies.