skip to content

Cipher Modes & Authenticated Encryption

The mode decides whether a block cipher is actually safe: ECB leaks structure, CBC and CTR need a unique unpredictable IV, and authenticated modes like GCM add an integrity tag. Interviewers ask what happens when a nonce is reused, and why confidentiality without integrity leaves you open to tampering and padding oracles.

part ofApplication security & secure codingoverview, primer and where to startread it →
on this pageshow

questions

5

Why is Electronic Codebook (ECB) mode considered unusable for general-purpose encryption, and what property must any acceptable mode have that ECB lacks?

level: juniorimportance: must knowfreq 62%

answer

  1. same block in → same block out
  2. encrypted image still shows the picture
  3. blocks reorderable: nothing binds position
  4. deterministic + small domain = dictionary attack
  5. fix is randomization (IV/nonce), not a stronger cipher

basics

~20 s

ECB encrypts each block independently with no randomization, so identical plaintext blocks give identical ciphertext blocks — it leaks structure, repetition and equality, and blocks can be reordered or spliced. Any usable mode must be randomized: same plaintext, different ciphertext each time.

solid answer

~50 s

ECB applies the block cipher to each block independently. That makes it a deterministic, stateless, position-independent map from plaintext block to ciphertext block. Three consequences follow. It **leaks equality**: repeated blocks in the message, or the same message encrypted twice, produce identical ciphertext — which is why an encrypted bitmap still shows its outline. It permits **cut-and-paste**: blocks can be reordered, duplicated or spliced between messages because nothing binds a block to its position or its message. And it makes ciphertext a **dictionary key** for low-entropy plaintexts — with few possible values the attacker just encrypts them all and matches. The property ECB lacks is *randomized* (or nonce-based) encryption: the same plaintext under the same key must produce unrelated ciphertexts, which is exactly what an IV or nonce buys. Note the cipher is fine; the mode is the defect. Deterministic encryption is occasionally chosen deliberately — for blind-index lookups — but then equality leakage is an accepted, scoped cost.

go deeper

for a junior

Say clearly that identical plaintext blocks give identical ciphertext blocks, so patterns show through, and that a usable mode randomizes with an IV or nonce.

for a middle

Add cut-and-paste of blocks and the dictionary attack on low-entropy fields, and state the required property as: same plaintext, same key, unrelated ciphertexts.

for a senior

Frame it as the failure of IND-CPA for any deterministic scheme, and generalise to encrypted columns where the equality relation itself is the disclosure.

for a principal

Discuss when equality leakage is a deliberate, scoped design decision (searchable fields, blind indexes) and how you bound it — which columns, what an adversary with the frequency distribution can infer, and what you write down to justify it.

## What ECB does Electronic Codebook is the most literal way to use a block cipher on a long message: chop the plaintext into blocks, encrypt each block with the key, concatenate the results. There is no chaining, no IV, no counter, no state. The name is accurate — the mode behaves as if you had a codebook mapping every possible plaintext block to its ciphertext block, and you look each one up independently. That construction is deterministic, stateless, and position-independent, and each of those three properties is a distinct defect. ## Defect 1: it leaks equality, and equality is structure Because the map is deterministic, *equal input blocks produce equal output blocks*. The attacker learns the pattern of repetition in the plaintext without learning any plaintext. The famous demonstration is an image: encrypt a bitmap in ECB and the shapes remain visible, because large uniform regions of the picture are repeated identical blocks that encrypt to repeated identical ciphertext. The point generalises far beyond images. Consider a database column of encrypted values: every row holding the same value has the same ciphertext, so you get the frequency distribution for free, and frequency plus a guess about the domain (country, diagnosis code, salary band, yes/no) often identifies the values outright. Consider a fixed-format record: the constant parts are identical across all records, which tells you exactly where the variable parts start. The same determinism means the *whole message* encrypted twice under the same key gives byte-identical ciphertext, so an observer can tell that the same thing was sent again. ## Defect 2: cut-and-paste Nothing binds a block to its offset or to the message it came from. An attacker who can collect ciphertext blocks can reorder them, delete some, duplicate others, or splice blocks from one message into another, and the result decrypts into well-formed blocks of plaintext in the new arrangement. If the record format is `account | amount | recipient` on block boundaries, swapping blocks between two intercepted records is a valid transaction. Note that this is a *modification* attack; it exists in unauthenticated CBC and counter modes too, in different forms. Randomizing the mode fixes the equality leak, not the tampering — that needs an authentication tag. ## Defect 3: the ciphertext is a lookup key When the plaintext block has low entropy — a boolean, a status code, a short identifier, a value from a list of a few thousand — an attacker who can get chosen plaintexts encrypted under the same key builds a dictionary and matches every ciphertext against it. Determinism turns encryption into a reversible encoding for small domains. ## The property that is missing Any acceptable general-purpose mode must be **randomized or nonce-based**: encrypting the same plaintext twice under the same key must yield ciphertexts an adversary cannot relate. Formally this is what indistinguishability under chosen-plaintext attack demands, and a deterministic scheme cannot achieve it — the adversary submits the same message twice and compares. The randomizing element is the initialization vector or nonce: chained into the first block in CBC, or fed into the counter block in counter-style modes. Its handling is a contract in its own right (uniqueness, and in some modes unpredictability), which is a separate topic — but the reason it exists at all is precisely to destroy determinism. ## The cipher is not the problem A common confusion is to treat "ECB is broken" as a statement about the cipher. It is not: the underlying permutation is unchanged, and it is the *composition* that leaks. This is the general lesson of the whole area — the primitive is rarely where things fail; how it is composed into a scheme is. The same shape of defect shows up wherever a deterministic transform is applied to low-entropy or repetitive data: an unsalted digest of a small domain lets you precompute matches (the hashing topic owns that), and textbook, unpadded public-key encryption is deterministic for the same reason (the asymmetric topic owns that). Recognising the shape — *determinism plus a guessable domain equals disclosure* — is more valuable than memorising the ECB case. ## When determinism is deliberate There is a legitimate niche: you sometimes need equality lookups over encrypted data, so a deterministic construction (or a keyed blind index) is chosen on purpose. This is a *considered trade*, not an exception to the rule. The correct framing is: you have decided to publish the equality relation over that column, you have scoped it to a column whose equality pattern you can afford to leak, and you have not made the value itself recoverable. It never justifies ECB over a whole record. ## The ladder Structural separation here means choosing a standard authenticated, randomized mode so the properties come from the construction rather than from your care. The rungs below — transforming the data before encryption to break up repetition, validating that plaintexts look unique, detecting duplicate ciphertexts in monitoring — are all heuristics people have actually shipped in place of fixing the mode, and each is weaker than the one above it.

  • Does switching from ECB to CBC make the ciphertext safe?
    It removes the equality leak, provided the IV is unique and unpredictable, but it does not add integrity. CBC without a tag is still malleable — an attacker who modifies one ciphertext block flips chosen bits in the next plaintext block — and it is still vulnerable to replay and truncation. The complete fix is a randomized *and* authenticated construction.
  • Is there any situation where deterministic encryption of a field is acceptable?
    Yes, when you need equality search over encrypted data and you can afford to publish the equality relation for that field. That is normally done with a keyed blind index rather than raw ECB, restricted to one column, and only after deciding that duplicate detection and frequency analysis on that column are tolerable. It is a scoped trade-off with a written justification, not a default.

ECB is a substitution cipher whose alphabet happens to be 16-byte blocks instead of letters. Frequency analysis broke letter substitution centuries ago, and it works on blocks for exactly the same reason.

saying these in an interview costs you the question

  • Saying ECB is unsafe because the cipher or key size is weak, rather than because the mode is deterministic.
  • Believing ECB is fine as long as the message is shorter than one block — that removes the repetition inside the message but not the identical-ciphertext-for-identical-message leak.
  • Thinking the fix is to compress or scramble the plaintext first.
  • Assuming that moving off ECB also solves tampering.

context

open as a page

Encryption is usually described as "nobody else can read it." Give the definition of what a block-cipher mode of operation actually guarantees, and explain why a ciphertext an attacker can modify in a predictable way is insecure even when they can never read it.

level: middleimportance: must knowfreq 60%

basics

~20 s

A mode gives confidentiality only — it hides content, not length and not authenticity. Unauthenticated ciphertext is malleable: an attacker can flip plaintext bits blindly. Authenticated encryption adds a tag, so any modified ciphertext is rejected instead of decrypted.

open as a page

State the contract an initialization vector or nonce must satisfy in CBC-style and counter-style encryption modes, and describe exactly what an attacker gains when the same nonce is reused under the same key.

level: seniorimportance: must knowfreq 48%

basics

~20 s

CBC needs an IV that is unique and unpredictable. Counter-style modes need only uniqueness, but absolutely: reuse XORs two plaintexts together, and in a Galois-tag mode it also leaks the authentication subkey, letting the attacker forge any message under that key.

open as a page

A service decrypts attacker-supplied ciphertext and returns one error for "bad padding" and a different one for "bad content." Explain the general class of attack this enables, and state the ordering rule for encryption and authentication that prevents it.

level: seniorimportance: should knowfreq 42%

basics

~20 s

Any behaviour that differs based on decrypted bytes turns the service into a decryption oracle; a padding check leaks enough to recover plaintext byte by byte without the key. Fix: authenticate the ciphertext and reject before decrypting — encrypt-then-MAC, or an authenticated mode.

open as a page

You are designing the on-disk format for encrypting many records with a symmetric key. Walk through the decisions — nonce strategy, what belongs in the associated data, how many records one key may protect — and say what an authenticated mode still does not protect against.

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Store a versioned header — format version, key id, nonce — and authenticate all of it plus the record's identity as associated data. Bound messages per key so nonces cannot collide. An authenticated mode still misses replay, rollback, record deletion, length leakage and key ambiguity.

open as a page