Skip to content

AES initialization vector isn't random #1

@12232132

Description

@12232132

https://github.com/informationextraction/scout-win/blob/master/core-scout-win32/crypt.cc#L12
From https://en.wikipedia.org/wiki/Initialization_vector :
"Randomization is crucial for encryption schemes to achieve semantic security, a property whereby repeated usage of the scheme under the same key does not allow an attacker to infer relationships between segments of the encrypted message."
This looks more like a poor security practice, rather than a critical flaw.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions