7 ms·
You immediately lose your integrity protections, which allows you to launch attacks against AES-CTR as if it had no authentication tag. https://cryptologie.net
by CiPHPerCoder 7y ago
You immediately lose your integrity protections, which allows you to launch attacks against AES-CTR as if it had no authentication tag.
https://cryptologie.net/article/361/breaking-https-aes-gcm-or-a-part-of-it/ https://cryptologie.net/article/361/breaking-https-aes-gcm-o...
- amluto 7y agoYou also learn the XOR or the two plaintexts, which can be a catastrophic loss of confidentiality.
- joe_xyz 7y agoYou can also determine the keyed hash function key if you collect enough plaintexts, which would let you forge authentication tags https://csrc.nist.gov/csrc/media/projects/block-cipher-techniques/documents/bcm/comments/800-38-series-drafts/gcm/joux_comments.pdf https://csrc.nist.gov/csrc/media/projects/block-cipher-techn...
- throwaway2048 7y agoIts worse than that with AES-GCM, nonce reuse reveals the AES private key.