Typescript Predictable Iv Nonce Source
Description
This vulnerability detector identifies the use of predictable or weak sources for initialization vectors (IVs) or nonces in TypeScript cryptographic operations. Predictable IVs/nonces can compromise the security of encryption algorithms, allowing attackers to potentially decrypt data or perform cryptographic attacks by exploiting the predictable values.
Detection Strategy
• Scans TypeScript source code for cryptographic function calls that require initialization vectors or nonces
• Identifies when IVs or nonces are generated using predictable sources such as hardcoded values, simple counters, current timestamps, or weak random number generators
• Reports violations when cryptographic operations use deterministic or easily guessable values instead of cryptographically secure random sources
• Flags usage of insecure IV/nonce generation patterns that could compromise encryption security
Vulnerable code example
import * as crypto from 'crypto';
function encryptWithPredictableIv(key: Buffer, data: Buffer): Buffer {
// VULNERABLE: IV derived from Date.now() is predictable
const cipher = crypto.createCipheriv(
'aes-256-cbc',
key,
Buffer.from(Date.now().toString().padStart(16, '0'))...✅ Secure code example
import * as crypto from 'crypto';
function encryptWithPredictableIv(key: Buffer, data: Buffer): Buffer {
// SAFE: IV generated randomly instead of from predictable Date.now()
const cipher = crypto.createCipheriv(
'aes-256-cbc',
key,
crypto.randomBytes(16) // Use cryptographically secure random IV...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.