Suppose the Kerberos V5 password to key conversion function is identical to V4, but then takes the output that V4 would compute and XORs it with the realm name. This would produce a different key in each realm, as desired. What is wrong with this algorithm?
