A server signs data as H(secret || data). You've intercepted one
message (the secret is never sent). Can you extend it into something the server never signed
— and still pass the MAC check — without ever learning the secret?
The intercepted message (this is all an attacker ever sees on the wire):
What you compute (never touching the secret):
Forged cookie you'd send back
H(secret || data)H(secret || H(data))