3 ms·
This is a great paper. Basically, AES-GCM fails when nonces are repeated. If that sounds like a impossibility, it isn't. The authors found several TLS implement
by kkl 10y ago
This is a great paper. Basically, AES-GCM fails when nonces are repeated. If that sounds like a impossibility, it isn't. The authors found several TLS implementations that had faulty nonce generation algorithms. Notably, one device would send the same 8 bytes of uninitialized memory as it's first and second nonce in a connection.