Cryptography Advanced

Block Cipher Modes: ECB vs CBC

A block cipher only encrypts one fixed-size block. How you chain the blocks together is the mode, and it matters enormously — encrypt the same image in ECB and in CBC and the difference is visible from across the room.

Side-by-side image encryption
Block-level inspection
IV reuse demonstrated
Live
Source and Settings
Image128 × 128 pixels
Total blocks256
Distinct blocks—
Repeated blocks—
The cipher here is a small keyed permutation, not AES — but it is a genuine deterministic block cipher, and that is the only property this demonstration depends on.
Encrypted Three Ways
Original
The plaintext image
ECB mode
Encrypted — and you can still see it
CBC mode
Encrypted — indistinguishable from noise
Why ECB leaks: the first 24 blocks

Each chip is a block's ciphertext fingerprint. Red means that exact value appeared earlier — identical plaintext, identical ciphertext, pattern preserved.

How the Two Modes Differ
ECB — each block alone
P₁ → Ek → C₁
P₂ → Ek → C₂
P₃ → Ek → C₃

Nothing connects the blocks. P₁ = P₃ forces C₁ = C₃, so every repetition in the plaintext is a repetition in the ciphertext. Blocks can also be reordered, deleted or replayed without detection.

CBC — each block feeds the next
P₁ ⊕ IV → Ek → C₁
P₂ ⊕ C₁ → Ek → C₂
P₃ ⊕ C₂ → Ek → C₃

Every block is XORed with the previous ciphertext before encryption, so identical plaintext blocks encrypt differently depending on everything before them. A random IV makes even the same message encrypt differently each time.

A Block Cipher Is Not a Cipher Yet
ECB: C_i = E_k(P_i) CBC: C_i = E_k(P_i XOR C_(i-1))

AES encrypts exactly 128 bits. Real messages are longer, so something must decide how to apply it repeatedly — that decision is the mode of operation, and it is where most of the security lives.

ECB (Electronic Codebook) simply encrypts each block independently. It is the obvious choice and it is almost always wrong: equal plaintext blocks produce equal ciphertext blocks, so structure survives encryption. The image above is the standard demonstration.

CBC (Cipher Block Chaining) XORs each plaintext block with the previous ciphertext block first. Now every block depends on all the blocks before it, and a random IV makes the whole ciphertext different every time.

The cipher itself is identical in both pictures. Only the wiring around it changed — which is exactly the point.
Choosing a Mode Today

ECB has no legitimate use for real data. But CBC is not the modern answer either:

  • CBC provides no integrity. An attacker who flips a ciphertext bit flips the corresponding plaintext bit in the next block, undetected. Padding-oracle attacks on CBC broke real systems for years.
  • The IV must be random and unpredictable, not a counter and never reused. A predictable IV was the flaw behind the BEAST attack on TLS.
  • CTR mode turns a block cipher into a stream cipher and parallelises well — but reusing a counter value is exactly the two-time pad disaster.
  • GCM is the current default, and it is what you should reach for: CTR mode plus an authentication tag, so tampering is detected rather than silently decrypted. TLS 1.3 permits only authenticated modes like this.
The rule that follows from all of it: use authenticated encryption. Confidentiality without integrity is a bug, not a trade-off.
Put It Into Practice

The tool shows the mechanism — the slides show why it is built that way.

The picture that teaches the lesson

Everyone remembers the ECB penguin. One-on-one tutoring goes further — padding oracles, IV handling, and why authenticated encryption is now the only defensible choice.

Book a Free Consultation →