the key has a fixed len: do not hardcode it
and add a safeguard in case the caller provides a key with the wrong size