Hacker News new | ask | show | jobs
by technion 2704 days ago
Addressing the debate this thread seems to have spawned, a practical attack on predictable CBC IVs is described here:

https://stackoverflow.com/questions/3008139/why-is-using-a-n...

Therefore in a strict sense, this is "broken". However, the "I zipped a file and it to someone" scenario is not one in which the above attack is practical.