Use of weak cryptography

Review weak cryptography and use encryption with key management and integrity verification.

Description

Algorithms with known weaknesses or unsuitable modes may fail to protect data confidentiality or integrity. DES's short key and ECB's exposure of patterns are examples. Check the mode, key management, and tamper detection as well as the algorithm name.

Potential impact

  • An attacker who obtains ciphertext may break weak encryption and access sensitive information.
  • Without integrity verification, the application may process modified ciphertext.
  • If the exposed data contains credentials, it may enable unauthorized access to accounts or services.

Remediation

  • Use authenticated encryption such as AES-GCM from a reviewed library for data encryption.
  • Generate and store keys securely, never reuse a nonce with the same key, and verify the authentication tag during decryption.
  • Plan migration based on the existing ciphertext format and keys, following applicable OWASP and NIST guidance.

Examples

These examples use PyCryptodome. Generating a new key in memory is for demonstration; a real system must manage keys in a protected store.

Before

python
# Unsafe DES encryption
from Crypto.Cipher import DES
from Crypto.Util.Padding import pad

key = b'8bytekey'  # 56비트 DES 키
cipher = DES.new(key, DES.MODE_ECB)
plaintext = b'This is a secret message.'
ciphertext = cipher.encrypt(pad(plaintext, DES.block_size))

After

python
# Authenticated AES encryption
from Crypto.Cipher import AES
from Crypto.Random import get_random_bytes

key = get_random_bytes(32)  # 256비트 AES 키
cipher = AES.new(key, AES.MODE_GCM)
plaintext = b'This is a secret message.'
ciphertext, tag = cipher.encrypt_and_digest(plaintext)
nonce = cipher.nonce

receiver = AES.new(key, AES.MODE_GCM, nonce=nonce)
recovered = receiver.decrypt_and_verify(ciphertext, tag)

Explanation

  • Before: Padding only aligns the block length. DES's 56-bit key and the weaknesses of ECB remain.
  • After: AES-GCM encrypts the data and verifies the tag when decrypting. Store or transmit nonce, tag, and ciphertext together while protecting the key separately. Do not use the decrypted result if verification fails.

References