Wednesday, September 16, 2020

Blank IVs - Not Even Once

from here

This may go over a lot of people's heads, but as someone who has encountered crypto code that ignores initialization vectors because the programmer was just following examples in MSDN, the fact that Microsoft themselves have mishandled IVs in their own code just fills me with such schadenfreude.