Announcing AES-GEM (AES with Galois Extended Mode)
By Scott Arciszewski
Today, AES-GCM is one of two cipher modes used by TLS 1.3 (the other being ChaCha20-Poly1305) and the preferred method for encrypting data in FIPS-validated modules. But despite its overwhelming success, AES-GCM has been the root cause of some catastrophic failures: for example, Hanno Böck and Sean Devlin exploited nonce misuse to inject their Black Hat USA slide deck into the MI5 website.
Security researchers have been sounding the alarm about AES-GCM’s weaknesses for years...
Read more at blog.trailofbits.com