[{"data":1,"prerenderedAt":800},["ShallowReactive",2],{"navigation_docs":3,"-ciphers-aes-ofb":204,"-ciphers-aes-ofb-surround":795},[4,36],{"title":5,"path":6,"stem":7,"children":8,"icon":35},"Guide","\u002Fguide","1.guide\u002F01.index",[9,11,15,19,23,27,31],{"title":10,"path":6,"stem":7},"Getting Started",{"title":12,"path":13,"stem":14},"Encode and decode","\u002Fguide\u002Ftransform","1.guide\u002F02.transform",{"title":16,"path":17,"stem":18},"Analysis","\u002Fguide\u002Fanalysis","1.guide\u002F03.analysis",{"title":20,"path":21,"stem":22},"CLI","\u002Fguide\u002Fcli","1.guide\u002F04.cli",{"title":24,"path":25,"stem":26},"Agents","\u002Fguide\u002Fagents","1.guide\u002F05.agents",{"title":28,"path":29,"stem":30},"Custom ciphers","\u002Fguide\u002Fcustom","1.guide\u002F06.custom",{"title":32,"path":33,"stem":34},"Playground","\u002Fguide\u002Fplayground","1.guide\u002F07.playground","i-solar-book-2-linear",{"title":37,"path":38,"stem":39,"children":40,"icon":203},"Ciphers","\u002Fciphers","2.ciphers\u002F00.index",[41,43,47,51,55,59,63,67,71,75,79,83,87,91,95,99,103,107,111,115,119,123,127,131,135,139,143,147,151,155,159,163,167,171,175,179,183,187,191,195,199],{"title":42,"path":38,"stem":39},"Overview",{"title":44,"path":45,"stem":46},"Caesar","\u002Fciphers\u002Fcaesar","2.ciphers\u002F01.caesar",{"title":48,"path":49,"stem":50},"ROT-13","\u002Fciphers\u002Frot13","2.ciphers\u002F02.rot13",{"title":52,"path":53,"stem":54},"ROT-47","\u002Fciphers\u002Frot47","2.ciphers\u002F03.rot47",{"title":56,"path":57,"stem":58},"Atbash","\u002Fciphers\u002Fatbash","2.ciphers\u002F04.atbash",{"title":60,"path":61,"stem":62},"Affine","\u002Fciphers\u002Faffine","2.ciphers\u002F05.affine",{"title":64,"path":65,"stem":66},"Vigenère","\u002Fciphers\u002Fvigenere","2.ciphers\u002F06.vigenere",{"title":68,"path":69,"stem":70},"Trithemius","\u002Fciphers\u002Ftrithemius","2.ciphers\u002F07.trithemius",{"title":72,"path":73,"stem":74},"Alberti","\u002Fciphers\u002Falberti","2.ciphers\u002F08.alberti",{"title":76,"path":77,"stem":78},"Playfair","\u002Fciphers\u002Fplayfair","2.ciphers\u002F09.playfair",{"title":80,"path":81,"stem":82},"Polybius square","\u002Fciphers\u002Fpolybius","2.ciphers\u002F10.polybius",{"title":84,"path":85,"stem":86},"Morse code","\u002Fciphers\u002Fmorse","2.ciphers\u002F11.morse",{"title":88,"path":89,"stem":90},"Bacon's cipher","\u002Fciphers\u002Fbacon","2.ciphers\u002F12.bacon",{"title":92,"path":93,"stem":94},"Tap code","\u002Fciphers\u002Ftap-code","2.ciphers\u002F13.tap-code",{"title":96,"path":97,"stem":98},"ADFGVX","\u002Fciphers\u002Fadfgvx","2.ciphers\u002F14.adfgvx",{"title":100,"path":101,"stem":102},"Bifid","\u002Fciphers\u002Fbifid","2.ciphers\u002F15.bifid",{"title":104,"path":105,"stem":106},"Rail fence","\u002Fciphers\u002Frail-fence","2.ciphers\u002F16.rail-fence",{"title":108,"path":109,"stem":110},"Columnar transposition","\u002Fciphers\u002Fcolumnar","2.ciphers\u002F17.columnar",{"title":112,"path":113,"stem":114},"Enigma M3","\u002Fciphers\u002Fenigma","2.ciphers\u002F18.enigma",{"title":116,"path":117,"stem":118},"Beaufort","\u002Fciphers\u002Fbeaufort","2.ciphers\u002F19.beaufort",{"title":120,"path":121,"stem":122},"Autokey","\u002Fciphers\u002Fautokey","2.ciphers\u002F20.autokey",{"title":124,"path":125,"stem":126},"AES (ECB)","\u002Fciphers\u002Faes","2.ciphers\u002F21.aes",{"title":128,"path":129,"stem":130},"Triple DES (ECB)","\u002Fciphers\u002Ftriple-des","2.ciphers\u002F22.triple-des",{"title":132,"path":133,"stem":134},"AES (LRW)","\u002Fciphers\u002Faes-lrw","2.ciphers\u002F23.aes-lrw",{"title":136,"path":137,"stem":138},"AES (CBC)","\u002Fciphers\u002Faes-cbc","2.ciphers\u002F24.aes-cbc",{"title":140,"path":141,"stem":142},"AES (CFB)","\u002Fciphers\u002Faes-cfb","2.ciphers\u002F25.aes-cfb",{"title":144,"path":145,"stem":146},"AES (CTR)","\u002Fciphers\u002Faes-ctr","2.ciphers\u002F26.aes-ctr",{"title":148,"path":149,"stem":150},"AES (CCM)","\u002Fciphers\u002Faes-ccm","2.ciphers\u002F27.aes-ccm",{"title":152,"path":153,"stem":154},"AES (OFB)","\u002Fciphers\u002Faes-ofb","2.ciphers\u002F28.aes-ofb",{"title":156,"path":157,"stem":158},"AES (OCB)","\u002Fciphers\u002Faes-ocb","2.ciphers\u002F29.aes-ocb",{"title":160,"path":161,"stem":162},"Triple DES (CBC)","\u002Fciphers\u002Ftriple-des-cbc","2.ciphers\u002F30.triple-des-cbc",{"title":164,"path":165,"stem":166},"Rijndael (ECB)","\u002Fciphers\u002Frijndael","2.ciphers\u002F31.rijndael",{"title":168,"path":169,"stem":170},"AES (XTS)","\u002Fciphers\u002Faes-xts","2.ciphers\u002F32.aes-xts",{"title":172,"path":173,"stem":174},"AES (CBC-MAC)","\u002Fciphers\u002Faes-cbc-mac","2.ciphers\u002F33.aes-cbc-mac",{"title":176,"path":177,"stem":178},"Blowfish (ECB)","\u002Fciphers\u002Fblowfish","2.ciphers\u002F34.blowfish",{"title":180,"path":181,"stem":182},"DES (ECB)","\u002Fciphers\u002Fdes","2.ciphers\u002F35.des",{"title":184,"path":185,"stem":186},"DESX (ECB)","\u002Fciphers\u002Fdesx","2.ciphers\u002F36.desx",{"title":188,"path":189,"stem":190},"IDEA (ECB)","\u002Fciphers\u002Fidea","2.ciphers\u002F37.idea",{"title":192,"path":193,"stem":194},"Lucifer (ECB)","\u002Fciphers\u002Flucifer","2.ciphers\u002F38.lucifer",{"title":196,"path":197,"stem":198},"MARS (ECB)","\u002Fciphers\u002Fmars","2.ciphers\u002F39.mars",{"title":200,"path":201,"stem":202},"Serpent (ECB)","\u002Fciphers\u002Fserpent","2.ciphers\u002F40.serpent","i-solar-library-linear",{"id":205,"title":152,"body":206,"description":788,"extension":789,"links":790,"meta":791,"navigation":792,"path":153,"seo":793,"stem":154,"__hash__":794},"docs\u002F2.ciphers\u002F28.aes-ofb.md",{"type":207,"value":208,"toc":784},"minimark",[209,213,217,220,223,235,400,412,469,472,477,491,532,543,547,553,629,639,753,756,777,780],[210,211],"cipher-facts",{"name":212},"aes-ofb",[214,215,216],"p",{},"OFB is output feedback, the fourth mode in NIST SP 800-38A after ECB, CBC and CFB. It's a keystream like CFB and CTR, made the laziest way possible. AES encrypts the IV. That's the first 16 bytes of keystream. Then AES encrypts that result, and that's the next 16. And again, until the text runs out. Each keystream block gets XORed into its block of text.",[214,218,219],{},"What goes back in is AES's own output, never the text and never the ciphertext. So the keystream depends on the key and the IV and nothing else. You could compute a megabyte of it before the message even exists. The price is that block 5 needs blocks 1 to 4 first, so unlike CTR you can't jump straight to the middle.",[214,221,222],{},"Like CTR, encrypting and decrypting are the same XOR, AES only runs forward, and there's no padding. Fourteen bytes of text give fourteen bytes of ciphertext.",[214,224,225,226,230,231,234],{},"The key is 32, 48 or 64 hex digits, ",[227,228,229],"code",{},"iv"," is 32 and it's required. ",[227,232,233],{},"decode"," wants hex back, any whole number of bytes.",[236,237,242],"pre",{"className":238,"code":239,"language":240,"meta":241,"style":241},"language-ts shiki shiki-themes github-light github-light poimandres","const ofb = create(\"aes-ofb\");\nconst key = \"2b7e151628aed2a6abf7158809cf4f3c\";\nconst iv = \"000102030405060708090a0b0c0d0e0f\";\nofb.encode(\"ATTACK AT DAWN\", { key, iv }).text; \u002F\u002F \"11aa338dda2612f78e2973a8cce1\"\nofb.decode(\"11aa338dda2612f78e2973a8cce1\", { key, iv }).text; \u002F\u002F \"ATTACK AT DAWN\"\n","ts","",[227,243,244,280,301,320,365],{"__ignoreMap":241},[245,246,249,253,257,260,264,268,272,275,277],"span",{"class":247,"line":248},"line",1,[245,250,252],{"class":251},"s1TYA","const",[245,254,256],{"class":255},"saoiD"," ofb",[245,258,259],{"class":251}," =",[245,261,263],{"class":262},"sULi6"," create",[245,265,267],{"class":266},"sKlNE","(",[245,269,271],{"class":270},"scVjq","\"",[245,273,212],{"class":274},"sQ7BG",[245,276,271],{"class":270},[245,278,279],{"class":266},");\n",[245,281,283,285,288,290,293,296,298],{"class":247,"line":282},2,[245,284,252],{"class":251},[245,286,287],{"class":255}," key",[245,289,259],{"class":251},[245,291,292],{"class":270}," \"",[245,294,295],{"class":274},"2b7e151628aed2a6abf7158809cf4f3c",[245,297,271],{"class":270},[245,299,300],{"class":266},";\n",[245,302,304,306,309,311,313,316,318],{"class":247,"line":303},3,[245,305,252],{"class":251},[245,307,308],{"class":255}," iv",[245,310,259],{"class":251},[245,312,292],{"class":270},[245,314,315],{"class":274},"000102030405060708090a0b0c0d0e0f",[245,317,271],{"class":270},[245,319,300],{"class":266},[245,321,323,327,330,333,335,337,340,342,345,347,350,352,355,358,361],{"class":247,"line":322},4,[245,324,326],{"class":325},"spVlQ","ofb",[245,328,329],{"class":266},".",[245,331,332],{"class":262},"encode",[245,334,267],{"class":266},[245,336,271],{"class":270},[245,338,339],{"class":274},"ATTACK AT DAWN",[245,341,271],{"class":270},[245,343,344],{"class":266},", {",[245,346,287],{"class":325},[245,348,349],{"class":266},",",[245,351,308],{"class":325},[245,353,354],{"class":266}," }).",[245,356,357],{"class":325},"text",[245,359,360],{"class":266},"; ",[245,362,364],{"class":363},"sjhu3","\u002F\u002F \"11aa338dda2612f78e2973a8cce1\"\n",[245,366,368,370,372,374,376,378,381,383,385,387,389,391,393,395,397],{"class":247,"line":367},5,[245,369,326],{"class":325},[245,371,329],{"class":266},[245,373,233],{"class":262},[245,375,267],{"class":266},[245,377,271],{"class":270},[245,379,380],{"class":274},"11aa338dda2612f78e2973a8cce1",[245,382,271],{"class":270},[245,384,344],{"class":266},[245,386,287],{"class":325},[245,388,349],{"class":266},[245,390,308],{"class":325},[245,392,354],{"class":266},[245,394,357],{"class":325},[245,396,360],{"class":266},[245,398,399],{"class":363},"\u002F\u002F \"ATTACK AT DAWN\"\n",[214,401,402,403,407,408,411],{},"Same bytes as ",[404,405,406],"a",{"href":141},"CFB"," and ",[404,409,410],{"href":145},"CTR"," give for this text. All three start with AES over the IV. The second block is where they part: CFB encrypts the ciphertext, CTR the IV plus one, OFB the first keystream block. OpenSSL agrees:",[236,413,417],{"className":414,"code":415,"language":416,"meta":241,"style":241},"language-bash shiki shiki-themes github-light github-light poimandres","printf %s \"ATTACK AT DAWN\" | openssl enc -aes-128-ofb -K 2b7e151628aed2a6abf7158809cf4f3c -iv 000102030405060708090a0b0c0d0e0f | xxd -p\n","bash",[227,418,419],{"__ignoreMap":241},[245,420,421,425,429,431,433,435,438,442,445,449,452,455,458,461,463,466],{"class":247,"line":248},[245,422,424],{"class":423},"s39Ir","printf",[245,426,428],{"class":427},"sX7Zv"," %s",[245,430,292],{"class":270},[245,432,339],{"class":274},[245,434,271],{"class":270},[245,436,437],{"class":251}," |",[245,439,441],{"class":440},"sseY5"," openssl",[245,443,444],{"class":427}," enc",[245,446,448],{"class":447},"sqT1Y"," -aes-128-ofb",[245,450,451],{"class":447}," -K",[245,453,454],{"class":427}," 2b7e151628aed2a6abf7158809cf4f3c",[245,456,457],{"class":447}," -iv",[245,459,460],{"class":427}," 000102030405060708090a0b0c0d0e0f",[245,462,437],{"class":251},[245,464,465],{"class":440}," xxd",[245,467,468],{"class":447}," -p\n",[214,470,471],{},"The mode is tested against the OFB-AES128, OFB-AES192 and OFB-AES256 vectors from NIST SP 800-38A, F.4.",[473,474,476],"h2",{"id":475},"flipping-bits","Flipping bits",[214,478,479,480,407,483,486,487,490],{},"The keystream never sees the ciphertext, so a flipped bit flips the same plaintext bit and nothing else, in any block. ",[227,481,482],{},"DAWN",[227,484,485],{},"DUSK"," differ by ",[227,488,489],{},"00140405",":",[236,492,494],{"className":238,"code":493,"language":240,"meta":241,"style":241},"ofb.decode(\"11aa338dda2612f78e2973bcc8e4\", { key, iv }).text;\n\u002F\u002F \"ATTACK AT DUSK\"\n",[227,495,496,527],{"__ignoreMap":241},[245,497,498,500,502,504,506,508,511,513,515,517,519,521,523,525],{"class":247,"line":248},[245,499,326],{"class":325},[245,501,329],{"class":266},[245,503,233],{"class":262},[245,505,267],{"class":266},[245,507,271],{"class":270},[245,509,510],{"class":274},"11aa338dda2612f78e2973bcc8e4",[245,512,271],{"class":270},[245,514,344],{"class":266},[245,516,287],{"class":325},[245,518,349],{"class":266},[245,520,308],{"class":325},[245,522,354],{"class":266},[245,524,357],{"class":325},[245,526,300],{"class":266},[245,528,529],{"class":247,"line":282},[245,530,531],{"class":363},"\u002F\u002F \"ATTACK AT DUSK\"\n",[214,533,534,535,538,539,542],{},"Works in a longer message too. The same flip turns ",[227,536,537],{},"ATTACK AT DAWN, RETREAT AT DUSK."," into ",[227,540,541],{},"ATTACK AT DUSK, RETREAT AT DUSK.",", second block untouched. There's no integrity check to notice.",[473,544,546],{"id":545},"same-keystream-twice","Same keystream twice",[214,548,549,550,552],{},"Same key and same ",[227,551,229],{},", same keystream, and XOR of two ciphertexts is XOR of the two texts, same as in CTR:",[236,554,556],{"className":238,"code":555,"language":240,"meta":241,"style":241},"ofb.encode(\"ATTACK AT DAWN\", { key, iv }).text; \u002F\u002F \"11aa338dda2612f78e2973a8cce1\"\nofb.encode(\"ATTACK AT DUSK\", { key, iv }).text; \u002F\u002F \"11aa338dda2612f78e2973bcc8e4\"\n\u002F\u002F XOR: \"0000000000000000000000140405\"\n",[227,557,558,590,624],{"__ignoreMap":241},[245,559,560,562,564,566,568,570,572,574,576,578,580,582,584,586,588],{"class":247,"line":248},[245,561,326],{"class":325},[245,563,329],{"class":266},[245,565,332],{"class":262},[245,567,267],{"class":266},[245,569,271],{"class":270},[245,571,339],{"class":274},[245,573,271],{"class":270},[245,575,344],{"class":266},[245,577,287],{"class":325},[245,579,349],{"class":266},[245,581,308],{"class":325},[245,583,354],{"class":266},[245,585,357],{"class":325},[245,587,360],{"class":266},[245,589,364],{"class":363},[245,591,592,594,596,598,600,602,605,607,609,611,613,615,617,619,621],{"class":247,"line":282},[245,593,326],{"class":325},[245,595,329],{"class":266},[245,597,332],{"class":262},[245,599,267],{"class":266},[245,601,271],{"class":270},[245,603,604],{"class":274},"ATTACK AT DUSK",[245,606,271],{"class":270},[245,608,344],{"class":266},[245,610,287],{"class":325},[245,612,349],{"class":266},[245,614,308],{"class":325},[245,616,354],{"class":266},[245,618,357],{"class":325},[245,620,360],{"class":266},[245,622,623],{"class":363},"\u002F\u002F \"11aa338dda2612f78e2973bcc8e4\"\n",[245,625,626],{"class":247,"line":303},[245,627,628],{"class":363},"\u002F\u002F XOR: \"0000000000000000000000140405\"\n",[214,630,631,632,635,636,638],{},"OFB has one more way to get there. The keystream is a chain, and every link is a valid IV. The first keystream block for the IV above is ",[227,633,634],{},"50fe67cc996d32b6da0937e99bafec60",". Encrypt something with that as ",[227,637,229],{}," and you get the old keystream, one block later:",[236,640,642],{"className":238,"code":641,"language":240,"meta":241,"style":241},"ofb.encode(\"A\".repeat(32), { key, iv }).text.slice(32);\n\u002F\u002F \"98e59b9b49d362de2aca7c37c1a01735\"\nofb.encode(\"A\".repeat(16), { key, iv: \"50fe67cc996d32b6da0937e99bafec60\" }).text;\n\u002F\u002F \"98e59b9b49d362de2aca7c37c1a01735\"\n",[227,643,644,696,701,749],{"__ignoreMap":241},[245,645,646,648,650,652,654,656,659,661,663,666,668,672,675,677,679,681,683,685,687,690,692,694],{"class":247,"line":248},[245,647,326],{"class":325},[245,649,329],{"class":266},[245,651,332],{"class":262},[245,653,267],{"class":266},[245,655,271],{"class":270},[245,657,658],{"class":274},"A",[245,660,271],{"class":270},[245,662,329],{"class":266},[245,664,665],{"class":262},"repeat",[245,667,267],{"class":266},[245,669,671],{"class":670},"siHFe","32",[245,673,674],{"class":266},"), {",[245,676,287],{"class":325},[245,678,349],{"class":266},[245,680,308],{"class":325},[245,682,354],{"class":266},[245,684,357],{"class":325},[245,686,329],{"class":266},[245,688,689],{"class":262},"slice",[245,691,267],{"class":266},[245,693,671],{"class":670},[245,695,279],{"class":266},[245,697,698],{"class":247,"line":282},[245,699,700],{"class":363},"\u002F\u002F \"98e59b9b49d362de2aca7c37c1a01735\"\n",[245,702,703,705,707,709,711,713,715,717,719,721,723,726,728,730,732,735,737,739,741,743,745,747],{"class":247,"line":303},[245,704,326],{"class":325},[245,706,329],{"class":266},[245,708,332],{"class":262},[245,710,267],{"class":266},[245,712,271],{"class":270},[245,714,658],{"class":274},[245,716,271],{"class":270},[245,718,329],{"class":266},[245,720,665],{"class":262},[245,722,267],{"class":266},[245,724,725],{"class":670},"16",[245,727,674],{"class":266},[245,729,287],{"class":325},[245,731,349],{"class":266},[245,733,308],{"class":734},"snHMy",[245,736,490],{"class":266},[245,738,292],{"class":270},[245,740,634],{"class":274},[245,742,271],{"class":270},[245,744,354],{"class":266},[245,746,357],{"class":325},[245,748,300],{"class":266},[245,750,751],{"class":247,"line":322},[245,752,700],{"class":363},[214,754,755],{},"So two different IVs can still share keystream, if one sits somewhere in the other's chain. With 2^128 possible blocks that's bad luck, not something that happens to an honest counter or a random IV, and NIST is fine with either. It happens when somebody takes a block that came out of AES under the same key and uses it as the next IV. Hand-made IVs in puzzles do that more often than you'd think.",[214,757,758,759,762,763,765,766,769,770,772,773,776],{},"A key that isn't 32, 48 or 64 hex digits is an ",[227,760,761],{},"InvalidOptionError",", so is an ",[227,764,229],{}," that isn't 32 hex digits. A missing key or IV is a ",[227,767,768],{},"MissingOptionError",". On ",[227,771,233],{},", an odd number of hex digits is a ",[227,774,775],{},"CipherError",". No padding means only the UTF-8 check catches a wrong key. Most wrong keys fail it, a short message can still come out as valid garbage.",[214,778,779],{},"No integrity check, plain TypeScript, not constant time. For puzzles and for seeing what keystream reuse looks like. Don't protect anything real with it.",[781,782,783],"style",{},"html pre.shiki code .s1TYA, html code.shiki .s1TYA{--shiki-light:#D73A49;--shiki-default:#D73A49;--shiki-dark:#91B4D5}html pre.shiki code .saoiD, html code.shiki .saoiD{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#E4F0FB}html pre.shiki code .sULi6, html code.shiki .sULi6{--shiki-light:#6F42C1;--shiki-default:#6F42C1;--shiki-dark:#E4F0FBD0}html pre.shiki code .sKlNE, html code.shiki .sKlNE{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#A6ACCD}html pre.shiki code .scVjq, html code.shiki .scVjq{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#A6ACCD}html pre.shiki code .sQ7BG, html code.shiki .sQ7BG{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#5DE4C7}html pre.shiki code .spVlQ, html code.shiki .spVlQ{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#E4F0FB}html pre.shiki code .sjhu3, html code.shiki .sjhu3{--shiki-light:#6A737D;--shiki-light-font-style:inherit;--shiki-default:#6A737D;--shiki-default-font-style:inherit;--shiki-dark:#767C9DB0;--shiki-dark-font-style:italic}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .s39Ir, html code.shiki .s39Ir{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#91B4D5}html pre.shiki code .sX7Zv, html code.shiki .sX7Zv{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#ADD7FF}html pre.shiki code .sseY5, html code.shiki .sseY5{--shiki-light:#6F42C1;--shiki-default:#6F42C1;--shiki-dark:#91B4D5}html pre.shiki code .sqT1Y, html code.shiki .sqT1Y{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#ADD7FF}html pre.shiki code .siHFe, html code.shiki .siHFe{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#5DE4C7}html pre.shiki code .snHMy, html code.shiki .snHMy{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#ADD7FF}",{"title":241,"searchDepth":282,"depth":282,"links":785},[786,787],{"id":475,"depth":282,"text":476},{"id":545,"depth":282,"text":546},"AES encrypting its own output. The IV goes in, every result goes back in for the next block, and the whole chain gets XORed into the text. UTF-8 text in, hex out, no padding, and decrypting is the same step.","md",null,{},true,{"title":152,"description":788},"4Zv1dG_NWRX-FkULerN_k_wfxwfrsXR5C_IE4cH_Tpw",[796,798],{"title":148,"path":149,"stem":150,"description":797,"children":-1},"AES in CTR mode with a CBC-MAC tag on the end. Decoding checks the tag first and refuses anything that was changed. UTF-8 text in, hex out, text bytes plus the tag.",{"title":156,"path":157,"stem":158,"description":799,"children":-1},"AES in OCB mode, RFC 7253. One AES call per block encrypts and authenticates at once, and decoding refuses anything that was changed. UTF-8 text in, hex out, text bytes plus the tag.",1790337933470]