Description
DES and 3DES are unsuitable for modern protection of sensitive data because of their small block size and outdated design.
Potential impact
- Increased exposure to cryptanalysis and brute-force attacks.
- Greater risk of sensitive data recovery.
- Failure to meet applicable requirements while relying on legacy encryption.
Remediation
- Replace DES/3DES with authenticated encryption such as AES-GCM.
- Separate legacy compatibility paths from sensitive-data processing and phase them out.
- Generate keys, IVs, and nonces using secure randomness and an appropriate key-management policy.
Examples
Before
The first excerpt configures CryptoSwift DES; the second calls CryptoKit AES-GCM. Library imports and key preparation are omitted, and key has a different type in each library.
swift
let des = try DES(key: key, blockMode: CBC(iv: iv), padding: .pkcs7)
After
swift
let sealedBox = try AES.GCM.seal(data, using: key)
Explanation:
- Before: DES is selected to encrypt sensitive data.
- After: AES-GCM uses a CryptoKit
SymmetricKey. Migrate to a new key and storage format rather than reusing the DES key.