Open cardosec

Case 95FC0A · Cryptography · L2 Practitioner

Block Cipher Modes

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. ECB encrypts identical blocks identically, leaking patterns (the ECB penguin); never use it for data.
  2. CBC needs an unpredictable IV and is malleable; it must be paired with a MAC (encrypt-then-MAC).
  3. CTR turns a block cipher into a stream cipher; reusing a nonce XORs plaintexts together.
  4. GCM is CTR plus GHASH authentication; 96-bit nonces must be unique per key or auth keys leak.

If the interviewer pushes back

  • Why is encrypt-then-MAC preferred over MAC-then-encrypt, and which TLS attacks exploited the latter?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.