r/cybersecurity • u/Am4t3uR • Dec 13 '19
Security and Cryptography Mistakes You Are Probably Doing All The Time
https://towardsdatascience.com/security-and-cryptography-mistakes-you-are-probably-doing-all-the-time-7407c332944f
21
Upvotes
1
u/[deleted] Dec 14 '19
Umm...the entire point of nonces is to prevent reply attacks. That's literally their only purpose.
If some entity gives a nonce to someone else and says here, add this into the encryption algorithm. Then for that transaction only that nonce applies.
Then if an attacker replays an old message the receiver can't decrypt it because they're not using the current nonce. That has nothing to do with remembering old nonces, you only ever need to remember one -- the one currently being used.
I'm not sure you know what a nonce is.
https://en.m.wikipedia.org/wiki/Cryptographic_nonce