Skip to content
Cryptography Reviewed 2026-09-13

Weak Symmetric Algorithm

Scope and impact

Legacy encryption such as DES, 3DES or RC4 is unsuitable for new protection of sensitive data. Merely changing an algorithm name to AES is insufficient: mode, authentication, nonce uniqueness and key management determine the result. OWASP's cryptographic storage guidance recommends authenticated encryption where available.

Node.js encryption example

Both examples accept plaintext bytes and a deployment-provisioned key of the required size. Key retrieval and storage are outside this excerpt; never embed or print the key.

Unsafe for new encryption: legacy 3DES without authentication.

import { createCipheriv, randomBytes } from 'node:crypto';
function encrypt(plaintext, key) { // legacy 24-byte key
  const iv = randomBytes(8);
  const cipher = createCipheriv('des-ede3-cbc', key, iv);
  const ciphertext = Buffer.concat([cipher.update(plaintext), cipher.final()]);
  return { iv, ciphertext };
}

Safer encryption primitive: AES-256-GCM with a fresh nonce and tag.

import { createCipheriv, randomBytes } from 'node:crypto';
function encrypt(plaintext, key) {
  if (!Buffer.isBuffer(key) || key.length !== 32) {
    throw new Error('Expected a 32-byte encryption key');
  }
  const nonce = randomBytes(12);
  const cipher = createCipheriv('aes-256-gcm', key, nonce,
    { authTagLength: 16 });
  const ciphertext = Buffer.concat([cipher.update(plaintext), cipher.final()]);
  return { nonce, ciphertext, tag: cipher.getAuthTag() };
}

Use a cryptographically generated key. Store the nonce and tag with the ciphertext; protect the key separately. Never reuse a nonce under the same key. Random nonces need per-key usage limits and rotation; this helper does not implement a high-volume key lifecycle.

For decryption, require the expected nonce/tag sizes, call setAuthTag, and reject any final() failure. Do not release output from update() before successful authentication. See the Node.js crypto contract. Version the stored format and plan migration of existing ciphertext separately.

Regression check

Round-trip a fictional value, then independently change the ciphertext, tag and key: each changed case must fail authentication without returning plaintext. Test empty plaintext too. Passwords require dedicated password hashing, not reversible encryption. See hardcoded keys, cipher modes and weak hashing.