EC-Council Certified Ethical Hacker (CEH) v12CryptographyMedium

An attacker has successfully exfiltrated a database containing encrypted credit card numbers. The encryption method used was AES-256 in Electronic Codebook (ECB) mode. What is the primary vulnerability introduced by using ECB mode for this type of data, even with a strong algorithm like AES-256?

  1. AIt is vulnerable to chosen-plaintext attacks, enabling full key recovery.
  2. BIt has a small block size, making it impractical for large data sets.
  3. CIt allows identical plaintext blocks to produce identical ciphertext blocks, revealing patterns.
  4. DIt is susceptible to brute-force attacks due to weak key management.
Show answer & explanation

Correct answer: C. It allows identical plaintext blocks to produce identical ciphertext blocks, revealing patterns.

ECB mode encrypts each block of plaintext independently. If the same plaintext block (e.g., a common credit card prefix or sequence) appears multiple times, it will always produce the exact same ciphertext block. This reveals patterns in the data, compromising confidentiality despite strong encryption, as depicted in the famous 'Tux' penguin example.

Why the other options are wrong

  • A. While some modes are vulnerable to chosen-plaintext, ECB's primary and most visible flaw is pattern leakage, not necessarily full key recovery.
  • B. AES has a 128-bit block size, which is standard and not considered small or impractical. The issue is the mode of operation, not the block size.
  • D. ECB mode itself doesn't inherently make it more susceptible to brute-force than other modes, nor does it dictate key management.

ECB Mode Vulnerability

Electronic Codebook (ECB) is a block cipher mode of operation where each plaintext block is encrypted independently. Its primary vulnerability is that identical plaintext blocks will always produce identical ciphertext blocks, revealing patterns in the data.

  • Encrypts blocks independently.
  • Reveals patterns in plaintext.
  • Not suitable for data with repeating blocks (e.g., images, structured data).
  • No initialization vector (IV) or chaining.

Memory trick: ECB is an exact copy, CBC chains, CTR counts, GCM does Galois.

More Cryptography questions