>> Rather puzzling, however: 1. They
>> claim that HMAC(key=constant, message=secret) is not provably a PRF.
> What's more puzzling is that we're not doing that.  We do
> HMAC(key=secret, message=constant).

They're talking about HKDF and the constant salt.  This is standard -
TextSecure does not have signed nonces to serve as an HKDF salt, so
the salt is constant (all zeros), per RFC 5869 or Hugo Krawczyk's

Moxie had good explanations of the other issues.


