4 ms·
> > They must be unpredictable > I am wondering if that is necessary, Yes, it is necessary. The IND security of Cipher Block Chaining (CBC) depends entirely o
by CiPHPerCoder 7y ago
> > They must be unpredictable
> I am wondering if that is necessary,
Yes, it is necessary. The IND security of Cipher Block Chaining (CBC) depends entirely on the IV being from a cryptographically secure random generator.
CBC mode requires unique and random IVs. CTR mode requires unique IVs (but can be predictable).
That's why we call the CTR input a nonce (number to be used once) and the CBC input an IV (initialization vector). Since they have different security requirements, we refer to them differently. Unfortunately, some cryptography libraries just name the parameter IV.
- metalliqaz 7y agoIs that distinction between nonce and IV held everywhere in the crypto community? For example, rfc8439 which defines the ChaCha-Poly AEAD does not require an unpredictable input nonce, and indeed calls it a "nonce", but many of the common implementations I've seen use "initialization vector" instead.
- CiPHPerCoder 7y agoLoosely. The majority have given up on the public understanding of nuances and just phone it in with "just don't write crypto". Because AES-CTR and ChaCha both refer to it as a nonce, and CBC calls it an initialization vector, the IV/nonce distinction does matter. But if you misuse the terms folks will know what you meant to say. Just don't mix it up when it comes time to implement.
- LookOutItsABot 7y agoPlease don't ever stop this behavior. I'm just learning much of this in an applicable way and people like you make this not just easier but possible for those of us learning with little outside help. The father I go down this rabbit hole the more I learn security should be like a religion of security (only one without dogma). Thanks.