Carelessness versus craftsmanship in cryptography
blog.trailofbits.com | blog | #vulnerability-research | #open-source | #cryptography | #vulnerability-disclosure | #trail-of-bits | #aes | #key-iv-reuse | #ctr-mode | #iv-reuse
Summary
The aes-js and pyaes libraries ship dangerous default IVs in their AES-CTR APIs, causing key/IV reuse bugs; Trail of Bits contrasts their dismissive maintainer with strongSwan's exemplary fix.
- Published
- Collected
Skip to content