AES-GCM Flaw Lets One Ciphertext Decrypt Validly Under Two Different Keys
A cryptographic weakness in widely used AEAD schemes like AES-GCM and ChaCha20-Poly1305 allows an attacker with two known keys to craft a single ciphertext that decrypts successfully and differently under each key, with neither producing an error. This property, called key non-commitment, stems from the linear structure of AES-GCM's authentication tag, which can be mathematically solved to satisfy two keys simultaneously. The vulnerability has real-world consequences: Facebook Messenger's message franking system, designed to let users report abusive content in end-to-end encrypted chats, was found exploitable because attachment encryption relied on AES-GCM without key commitment. An attacker could send an abusive image that, when reported, would verify as an entirely different, innocuous file, effectively defeating the abuse-reporting mechanism. The flaw was patched, but the broader lesson is that successful AEAD decryption does not prove which key or sender was involved — a guarantee these ciphers were never designed to provide.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in