Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš•
π•‚πšžπš‹πš’πš”β„™πš’πš‘πšŽπš•
@kubikpixel@chaos.social  Β·  activity timestamp 7 days ago

Carelessness versus craftsmanship in cryptography

Two popular AES libraries, aes-js and pyaes, β€œhelpfully” provide a default IV in their AES-CTR API, leading to a large number of key/IV reuse bugs. […] The aes-js/pyaes maintainer, on the other hand, has taken a more… cavalier approach.

πŸ”“ https://blog.trailofbits.com/2026/02/18/carelessness-versus-craftsmanship-in-cryptography/

#aesctr #itsecurity #key #javascript #js #iv #pyaes #cryptography #carelessness #aes #cybersecurity #cryptography #itsec #encryption #craftsmanship #reuse #fail

The Trail of Bits Blog

Carelessness versus craftsmanship in cryptography

Two popular AES libraries (aes-js and pyaes) provide dangerous default IVs that lead to key/IV reuse vulnerabilities affecting thousands of projects. One maintainer dismissed the issue, while strongSwan’s maintainer exemplified proper security response by comprehensively fixing the vulnerability in their VPN management tool.
  • Copy link
  • Flag this post
  • Block

Kakapo Social

Kakapo Social: About Β· Code of conduct Β· Privacy Β· Users Β· Instances
Bonfire social Β· 1.0.2-alpha.34 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct