Block Cipher Modes Lab
A block cipher like AES only knows how to transform one 16-byte block. A mode of operation decides how to chain those blocks into a full message — and that choice is where most real-world crypto goes right or wrong. Flip a single plaintext byte below and watch how far the damage spreads under each mode, then see why you should never encrypt an image with ECB.
key 2b7e1516… · iv 00010203…
The magic words are squeamish ossifrage.
ECBOnly the changed block differs; equal blocks stay equal.
16/48 bytes changed9aecf8bc24ca9b74df1c142ac9e920f7e2443d10a1b7dded2cc69e3126221c8b0576e48715c7810494cab3351e7d0400
CBCThe changed block and every block after it differ.
48/48 bytes changed1835b29a79fe9b8516780fc84edff9bf75cfea2d0b35902b8b29f588ee696fe53873e306111b030b3d670efe6c397d79
CFBOne byte in-block, then every following block differs.
25/40 bytes changed049602ecd80c55dfb9294086e9cb9f40219096ba8d173de612b9ac9a0aa8f71889689a4542f75a40
OFBKeystream is independent — only the one byte differs.
1/40 bytes changed049602ecd80c55dfb9294086e9cb9f40b8d6bffa7be356fa0ae65405e8c13907d4e17f2a5e646dc9
CTRCounter keystream — only the one byte differs.
1/40 bytes changed049602ecd80c55dfb9294086e9cb9f40ce53eb6ef492e6cfbb5c229713d7cc2ce583e9fb64e4f56c
The ECB Penguin
The same key encrypts the same image three ways. ECB encrypts each 16-byte block on its own, so the picture's flat regions produce repeating ciphertext blocks and the silhouette stays visible. A streaming mode like CTR masks every block differently, leaving nothing to see.