tricking the user into using a less secure algorithm