A method of implementing MAC with MAC(message,key)=Hash(key∣∣message) Formal Definition m=h(k∣∣x)=h(k∣∣∣x1∣∣…∣∣xn) In case of message x being larger than blocksize (like 512 for SHA) Vulnerability Secret Prefix Length Extension Attack