Case 2EBC10 · Cryptography · L4 Advanced
Repeated Nonces in Prod
Practise as: Incident drill · Interview
Live alertA code review finds the payments service encrypts card tokens with AES-256-GCM using a nonce from a counter that resets to 0 on every pod restart.
Interview questionYou discover AES-GCM nonce reuse in production. How bad is it and what do you do?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Same key+nonce reuses the CTR keystream: XOR of two ciphertexts equals XOR of plaintexts, leaking data.
- It also leaks the GHASH authentication key, letting an attacker forge valid ciphertexts (forbidden attack).
- Rotate the key now, re-encrypt stored data under the new key, and scope which records shared nonces.
- Fix nonce generation: random 96-bit nonces with rotation limits, or a nonce-misuse resistant AEAD (AES-GCM-SIV).
- Treat as a potential PCI DSS incident; document scope and involve the QSA if cardholder data was exposed.
If the interviewer pushes back
- At what number of encryptions does random 96-bit nonce collision become a concern, and how does that drive key rotation?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.