Skip to content

Symmetric vs asymmetric

Understanding the difference between symmetric and asymmetric encryption —and above all the modes of operation— is the basis for exploiting most real-world crypto flaws. The theory is simple; what’s exploitable lives in the usage details.

SYMMETRIC (AES, ChaCha20)
same key to encrypt and decrypt; fast; for large volumes of data
problem: how do the two parties share the key?
ASYMMETRIC (RSA, ECC)
key pair: public (encrypt/verify) + private (decrypt/sign); slow
solves key distribution and enables digital signatures
HYBRID (the real world: TLS, PGP, Signal)
asymmetric to exchange a session key -> symmetric for the data

AES encrypts 128-bit blocks. The mode says how blocks are chained, and that’s where flaws live:

ECB each block independent -> equal plaintext blocks = equal ciphertext
pattern LEAK (the "ECB penguin"); lets you cut/paste blocks. NEVER use.
CBC chains with XOR of the previous block; needs a random IV
malleable without a MAC (bit-flipping); vulnerable to padding oracle (crypto-padding)
CTR turns AES into a stream cipher (keystream XOR plaintext)
reusing (key,nonce) = CATASTROPHE: XOR of two texts reveals both
GCM CTR + authentication (AEAD) -> confidentiality + integrity. RECOMMENDED
UNIQUE nonce per key: repeating the nonce breaks authentication (forgery)
# encryption oracle: send repeated blocks and see repeated ciphertext
AAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAA -> two IDENTICAL encrypted blocks = ECB
# "ECB byte-at-a-time": if the server encrypts INPUT‖SECRET in ECB,
# you recover the secret byte by byte by aligning blocks (classic cryptopals challenge)

Keystream reuse (CTR/stream with repeated nonce)

Section titled “Keystream reuse (CTR/stream with repeated nonce)”
C1 = P1 XOR KS C2 = P2 XOR KS (same nonce -> same KS)
C1 XOR C2 = P1 XOR P2 -> "crib dragging" recovers both texts without the key

Malleability / bit-flipping (CBC without MAC)

Section titled “Malleability / bit-flipping (CBC without MAC)”
# flipping a byte in the CBC IV/ciphertext block changes, in a controlled way,
# the decrypted plaintext of the next block -> e.g. flip "role=user" to "role=admin"
  • PyCryptodome to build oracles and attacks; CyberChef to prototype.
  • openssl enc to encrypt/decrypt and reproduce modes; the cryptopals sets to practice.
  • AEAD by default: AES-GCM or ChaCha20-Poly1305; never raw CBC/CTR without a MAC.
  • Unique nonce per key (counter or random 96-bit in GCM); random IV in CBC.
  • Ban ECB. Encrypt-then-MAC if not using AEAD. Key rotation and management with KMS/HSM.
  • ECB in cookies/tokens: structure leak and block cut-paste, recurring in web audits.
  • Nonce reuse in GCM: authentication break; documented in misconfigured TLS and VPN implementations.
  • Zerologon (CVE-2020-1472) stems from incorrect use of AES-CFB8 with a fixed IV in Netlogon.
  • Identify algorithm and mode (block size 16 → AES)
  • ECB test: repeated blocks → repeated ciphertext
  • ECB byte-at-a-time if there’s an INPUT‖SECRET oracle
  • CTR/stream: look for nonce reuse (XOR of texts)
  • CBC without MAC: try bit-flipping and padding oracle (Padding oracle)
  • GCM: is the nonce repeated? → tag forgery
  • Verify the defense uses AEAD and a unique nonce