|
|
|
|
|
by SiebenHeaven
1571 days ago
|
|
I am pretty surprised how they allowed reusing IV. Unique IV is explicitly mentioned to be an assumption for AES GCM (first sentence in security section of AES-GCM wikipedia page) How could anyone design TA (i.e application whose whole point is security and hence it runs in the secure mode) and allow user to set IV in the API? |
|
I mean... TLS did the same (in 1.2, it was fixed in 1.3). I co-authored a paper about it: https://www.usenix.org/conference/woot16/workshop-program/pr...