4 ms·
I'm not sure why drum55's answer is buried but they're correct that the Nonce concept in modern crypto addresses this issue.
by tlhunter 1y ago
I'm not sure why drum55's answer is buried but they're correct that the Nonce concept in modern crypto addresses this issue.
- macintux 1y agoProbably because that's the user's only comment. I've vouched for it.
- conradludgate 1y agoIt's not only the nonce. The nonce helps to ensure that the message re-encrypted doesn't have the same ciphertext, but the known plaintext can still be used to forge messages. What stops message forgery is the message tag that TLS has (using the AEADs like AES-GCM or ChaCha20Poly1305). That said, the nonce is still very important to avoid most key recovery attacks
- Jweb_Guru 1y agoYeah the real answer here is that this is what AEADs are for.