Peel apart two messages — without ever touching the key

Bob's session reuses one AES-GCM nonce for every message (_FIXED_GCM_NONCE in broken_hybrid_encrypt.py). You've intercepted two of his ciphertexts — the session key is never sent, and you never see it here either. Can you recover real bytes of the second message using nothing but XOR and a guess about the first?

Session A's ciphertext bodies (this is all an eavesdropper ever sees on the wire — note: real AESGCM.encrypt() appends a 16-byte auth tag after this; this sim omits it so the XOR below stays readable, but a real proof script must slice it off first):

What you compute (the session key is never read):

Recovered fragment, both sessions

broken_hybrid_encrypt.py — fixed nonce

nonce = 00…00 for every message this session

fixed_hybrid_encrypt.py — fresh nonce per message

nonce = a counter, bumped once per message