Menu

#29 Encryption should be combined with signature

v2
open
Security (9)
5
2012-09-12
2011-06-28
John Downey
No

It is always recommended to compute a MAC signature of cyphertext and verify it before decryption. Failing to do so will leave you open to issues such as the recent ASP.NET padding oracle attack.

Discussion


Log in to post a comment.