Description
Reusing a fixed initialization vector (IV) with the same key in CBC encryption can reveal repeated plaintext prefixes. CBC requires a fresh, unpredictable IV for each encryption. Other modes have their own nonce or IV requirements.
Potential impact
- Information disclosure: Repeated plaintext patterns may reveal sensitive information.
- Data tampering: CBC alone does not provide integrity. Use authenticated encryption or separate authentication protection.
- Pattern analysis: Repeated IVs can reveal relationships between encrypted messages.
Remediation
- Use a fresh, unpredictable IV for each CBC encryption.
- Use a vetted cryptographic library to manage IVs correctly.
Examples
Before
python
# AES-CBC with a hardcoded IV
import os
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad
key = os.environ["ENCRYTION_KEY"].encode()
cipher = AES.new(key, AES.MODE_CBC, b'This is an IV456') # Hardcoded IV
plaintext = b'This is a secret message.'
ciphertext = cipher.encrypt(pad(plaintext, AES.block_size))
After
python
# AES-CBC with a fresh random IV
import os
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad
from Crypto.Random import get_random_bytes
key = os.environ["ENCRYTION_KEY"].encode()
iv = get_random_bytes(16) # Random IV
cipher = AES.new(key, AES.MODE_CBC, iv)
plaintext = b'This is a secret message.'
ciphertext = cipher.encrypt(pad(plaintext, AES.block_size))
Explanation:
- Before: A fixed IV makes relationships between encrypted data more predictable.
- After: A fresh random IV is generated for each encryption.