Typescript Key Derived Iv Nonce
Description
This vulnerability detector identifies cryptographic implementations in TypeScript that derive initialization vectors (IVs) or nonces from encryption keys, which is cryptographically insecure. Using key-derived IVs/nonces can lead to predictable or repeated values, compromising encryption security and potentially allowing attackers to decrypt data or perform cryptographic attacks.
Detection Strategy
• Scans TypeScript source code for cryptographic operations that generate initialization vectors (IVs) or nonces
• Identifies patterns where IVs or nonces are derived from encryption keys rather than being randomly generated
• Triggers when cryptographic functions use keys as input to generate IVs or nonces, violating cryptographic best practices
• Reports violations where the same key is used both for encryption and IV/nonce generation, creating security weaknesses
Vulnerable code example
import * as crypto from 'crypto';
function encryptWithSameIV(data: Buffer): Buffer {
const key = crypto.randomBytes(16);
// VULNERABLE: IV reuses the same bytes as the encryption key
const cipher = crypto.createCipheriv('aes-128-cbc', key, key);
return Buffer.concat([cipher.update(data), cipher.final()]);...✅ Secure code example
import * as crypto from 'crypto';
function encryptWithRandomIV(data: Buffer): Buffer {
const key = crypto.randomBytes(16);
// SECURE: Generate IV independently from key
const iv = crypto.randomBytes(16);
const cipher = crypto.createCipheriv('aes-128-cbc', key, iv);...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.