Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Padding oracles and the decline of CBC-mode cipher suites

Blog post from Cloudflare

Post Details
Company
Date Published
Author
Nick Sullivan
Word Count
2,755
Company Posts That Month
6
Language
English
Hacker News Points
63
Post removed?
No
Summary

Cipher block chaining (CBC) has been widely used in cryptography but has proven difficult to use safely. Recent trends in the adoption of secure ciphers by web clients have helped reduce the web's reliance on this technology. One solution to the issues with CBC is AEAD (Authenticated Encryption with Associated Data), which combines a stream cipher and an authentication step along the way rather than computing the MAC at the end. CloudFlare implements two such cipher modes, AES-GCM and ChaCha20-Poly1305. Adoption of AEAD cipher modes in clients is growing, with most modern browsers and operating systems supporting at least one AEAD cipher suite in their TLS software.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.