
10/12/2016 · Filippo Valsorda
What this post added
This post details the evolution of nonce management in TLS, explaining its importance for cryptographic security. It traces the progression from RC4's lack of nonces, through CBC's vulnerabilities in TLS 1.0 (BEAST attack) and its fixes in TLS 1.1 and 1.2, to the improved nonce handling in TLS 1.2 AES-GCM and the final robust implementation in TLS 1.3. It also highlights the "Nonce-Disrespecting Adversaries" vulnerability and the ongoing research into nonce reuse resistance.