{
  "id": 10491924,
  "title": "The Line of Code That Makes Every Encryption Unique — Even With the Same Password",
  "url": "https://urgent.news/2026/09/28/the-line-of-code-that-makes-every-encryption-unique-even-with-the",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-28T17:00:00.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/bijan53c/the-line-of-code-that-makes-every-encryption-unique-even-with-the-same-password-1bma"
  },
  "original_language": "en",
  "account": "An encryption system that generates the same ciphertext for identical plaintext under the same key poses a significant problem. If an attacker can observe these patterns, they can potentially break the encryption without actually cracking the key. This is known as leaking information through metadata and repetition, which is a distinct category of failure from confidentiality.\n\nIn the code used for encryption, a 12-byte nonce is generated for each call to the `encrypt()` function. This nonce is mixed into the AES-GCM encryption process, ensuring that the output is unique every time, even if the same key and message are used. The nonce is returned alongside the ciphertext so it can be used again during decryption. It is crucial that the nonce never repeats under the same key, as its only requirement is uniqueness.\n\nIf a nonce is reused with AES-GCM under the same key, the confidentiality of both messages encrypted with that repeated nonce can be fully broken. In some cases, the attacker may even recover the authentication key used for the integrity tag, undermining the tamper-detection property. This is not a theoretical concern but a common real-world implementation bug in systems that otherwise appear secure.\n\nGenerating a fresh, random nonce for every single call to `encrypt()` is the only solution to prevent nonce reuse. This simple yet essential step ensures that accidental collisions are astronomically unlikely for any realistic volume of messages under a single key. The mitigation is straightforward and non-negotiable, and failing to implement it can lead to catastrophic security breaches in production systems.",
  "summary": "Same message. Same password. Same key. Two completely different ciphertexts. That's not a bug — it's a requirement, and it comes down to a single value that's easy to overlook: the nonce. This is the final post in a series documenting what I'm learning building CryptoGraphy . Why identical ciphertext for identical plaintext is a real problem If the same plaintext always produced the same…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}