paytm / Paytm_Node_Checksum

https://developer.paytm.com/docs/checksum/#node
14 stars 66 forks source link

Same Initialisation Vector #3

Open TheStarkster opened 3 years ago

TheStarkster commented 3 years ago

Its more of a suggestion than an issue that please use a new IV for every encryptions. this is even recommended by CTR security. Because reusing an IV leaks some information about the first block of plaintext

pawanpandey101 commented 2 years ago

@Paytm-Payments-Admin this seems important, a constant IV might make it easier for an attacker to guess the data, any ETA on this?