Skip to content

Conversation

@aidin36
Copy link

@aidin36 aidin36 commented Sep 16, 2020

Using a constant IV with CBC mode is vulnerable to some attacks.
On the other hand, IV can be public.

I changed the app to generate a random IV, and stores it at the beginning of the ciphered text. It makes the generated cipher a little more secure.

I also suggest using the random IV as the key's salt too. It makes the key unique in every encryption, making the cipher a little bit more secure.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant