Elixir Key Derived Iv Nonce
Description
This detector identifies Elixir code that uses key-derived initialization vectors (IVs) or nonces in encryption operations. Using the same key to derive both the encryption key and IV/nonce creates predictable patterns that can compromise the security of the encryption scheme, making it vulnerable to cryptographic attacks.
Detection Strategy
• Scans Elixir source code for encryption function calls that may use key-derived IVs or nonces
• Identifies function calls where the same cryptographic key material is used to generate both the encryption key and the initialization vector
• Reports vulnerabilities when encryption operations use predictable or key-derived initialization vectors instead of random values
• Focuses on cryptographic library calls in Elixir that implement symmetric encryption with potentially weak IV generation
Vulnerable code example
defmodule VulnerableExample do
def encrypt_data(data) do
key = :crypto.strong_rand_bytes(16)
# VULNERABLE: IV reuses the same bytes as the key
:crypto.crypto_one_time(:aes_128_ctr, key, key, data, true)
end
...✅ Secure code example
defmodule SecureExample do
def encrypt_data(data) do
key = :crypto.strong_rand_bytes(16)
# SAFE: IV generated independently, not reusing key bytes
iv = :crypto.strong_rand_bytes(16)
:crypto.crypto_one_time(:aes_128_ctr, key, iv, data, true)
end...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.