Double check if using default nonce everywhere is ok in creating the cipher stream for encryption and signatures.