Just in case it confuses people, when you are doing Matt's general attack that interoperably works with non-rogue systems, you find via exhaustive search a LEAF that corresponds to your selected Session Key/IV pair. IV synchronization problems only show up if you are using the less general "feed the LEAF back to the same processor" trick. Perry