Collected research
Exploiting The Not So Misuse-Resistant Authenticated Encryption API of OpenSSL
OpenSSL-backed AEAD decryption APIs in Ruby, PHP, Node.js, Rust and Erlang take the tag length from whatever tag is supplied, so code that never checks it accepts a one-byte tag, brute-forceable in 256 tries. An attacker can bit-flip GCM ciphertexts, decrypt them byte by byte with a format-validity oracle, and recover the GHASH key by nonce reuse to forge tags offline.
Record
- Published by
- sideni.xyz
- Topic
- Crypto
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of sideni.xyz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .