Skip to content

More on nonce reuse with AES-GCM

In my last post, I wrote why reusing nonces with AES-GCM completely breaks it. Coincidentally, Frederik Reiter also wrote about this, but his blog post goes into all the details that I left out. And it's even interactive. Go check it out!