3 ms·
If the attacker never gets a hold of a plaintext-ciphertext pair, how well does AES-GCM with nonce reuse hold up?
by RA2lover 2y ago
If the attacker never gets a hold of a plaintext-ciphertext pair, how well does AES-GCM with nonce reuse hold up?
- jfyi 2y agoIt breaks down to a primitive of repeating key xor. If you never had a plaintext you could potentially (depending on the content) collect enough ciphertexts to do frequency analysis on it. You'd recover the keystream at least partially, and then guess based on context to fill out the rest.