Weak cryptography

Weak cryptography

Description

Weak or unreviewed cryptography, such as DES, RC4, ECB mode, or custom XOR encryption, does not provide reliable confidentiality.

Potential impact

Attackers may decrypt ciphertext, tamper with messages, or expose confidential data.

Remediation

Use vetted libraries, modern algorithms, authenticated encryption, and secure key management.

Examples

Before

php
<?php
$ciphertext = openssl_encrypt($data, 'des-ecb', $key);

After

php
<?php
$key = getEncryptionKey();
$iv = random_bytes(openssl_cipher_iv_length('aes-256-gcm'));
$ciphertext = openssl_encrypt($data, 'aes-256-gcm', $key, OPENSSL_RAW_DATA, $iv, $tag);

Explanation:

  • Before: The example uses the obsolete DES algorithm in ECB mode.
  • After: The example uses authenticated encryption with a fresh IV for each operation and a securely managed key.

getEncryptionKey() must return a securely generated and stored 32-byte key. Handle encryption failures, store the IV and authentication tag with the ciphertext, and reject data if tag verification fails during decryption.

References