4 ms·
>it seems hard-coding an IV and giving the user the ability to disable randomization may unnecessarily make unwitting users vulnerable Yes. There's not a great
by sarakayakomzin 6y ago
>it seems hard-coding an IV and giving the user the ability to disable randomization may unnecessarily make unwitting users vulnerable
Yes. There's not a great reason to disable the randomization here. You're safe if each link uses a new key, but if it was possible for a user to use the same key and IV for a different link, an attacker with access to the first link could now use it to access the second.
https://en.wikipedia.org/wiki/Stream_cipher_attacks#Chosen-IV_attack https://en.wikipedia.org/wiki/Stream_cipher_attacks#Chosen-I...