    So HMAC hashes keys that are too long. Can a cryptography guru in the audience explain why this is bad?

      yes, there are now 2 instead of 1 acceptable brute force values, but if that’s a problem you have bigger ones

      So, not really at all.