Open cardosec

Case 2EBC10 · Cryptography · L4 Advanced

Repeated Nonces in Prod

Practise as: Incident drill · Interview

Live alertA code review finds the payments service encrypts card tokens with AES-256-GCM using a nonce from a counter that resets to 0 on every pod restart.

Interview questionYou discover AES-GCM nonce reuse in production. How bad is it and what do you do?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Same key+nonce reuses the CTR keystream: XOR of two ciphertexts equals XOR of plaintexts, leaking data.
  2. It also leaks the GHASH authentication key, letting an attacker forge valid ciphertexts (forbidden attack).
  3. Rotate the key now, re-encrypt stored data under the new key, and scope which records shared nonces.
  4. Fix nonce generation: random 96-bit nonces with rotation limits, or a nonce-misuse resistant AEAD (AES-GCM-SIV).
  5. Treat as a potential PCI DSS incident; document scope and involve the QSA if cardholder data was exposed.

If the interviewer pushes back

  • At what number of encryptions does random 96-bit nonce collision become a concern, and how does that drive key rotation?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.