logo

Database

Elixir Predictable Iv Nonce Source

Description

This detector identifies Elixir AEAD encryption functions that use predictable IV/nonce sources, which compromises cryptographic security. Predictable IVs/nonces can lead to cryptographic attacks like duplicate keystream attacks, allowing attackers to decrypt sensitive data or forge authenticated messages.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • AEAD encryption function calls are identified by checking if the function expression matches the AEAD sink pattern

    • The cipher argument is validated to ensure it's an AEAD cipher type using atom checking

    • The encrypt flag argument is verified to be set to true, confirming this is an encryption operation

    • The IV/nonce argument is analyzed to determine if it comes from a predictable source (like hardcoded values, sequential counters, or other non-random sources)

    • A vulnerability is reported when all conditions are met: AEAD function call with valid cipher, encrypt flag set to true, and IV/nonce from a predictable source

Vulnerable code example

defmodule PredictableNonce do
  def encrypt_data(key, data, aad) do
    # VULNERABLE: nonce derived from predictable system time
    :crypto.crypto_one_time_aead(
      :aes_256_gcm,
      key,
      Integer.to_string(:os.system_time(:millisecond)),
      data,...

✅ Secure code example

defmodule PredictableNonce do
  def encrypt_data(key, data, aad) do
    # SAFE: nonce is generated using cryptographically secure random bytes
    nonce = :crypto.strong_rand_bytes(12)
    
    :crypto.crypto_one_time_aead(
      :aes_256_gcm,
      key,...