Menu

#29 Encryption should be combined with signature

v2
open
Security (9)
5
2012-09-12
2011-06-28
John Downey
No

It is always recommended to compute a MAC signature of cyphertext and verify it before decryption. Failing to do so will leave you open to issues such as the recent ASP.NET padding oracle attack.

Discussion


Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.