We should return an decrypt integrity error on bad password with encrypted timestamp rather than just preauth failed.