4 ms·
As far as I can tell, the AesCryptoServiceProvider they are using inherits the default CBC mode from here: http://msdn.microsoft.com/en-us/library/system.secur
by sweis 13y ago
As far as I can tell, the AesCryptoServiceProvider they are using inherits the default CBC mode from here:
http://msdn.microsoft.com/en-us/library/system.security.cryptography.symmetricalgorithm(v=vs.110).aspx http://msdn.microsoft.com/en-us/library/system.security.cryp...
So, it appears to be using CBC. However, their ciphertext is not authenticated so is still insecure.
- stevehaunts 13y agoI will add hmac authentication of the cipher text.