Bob's session reuses one AES-GCM nonce for every message
(_FIXED_GCM_NONCE in broken_hybrid_encrypt.py). You've intercepted two
of his ciphertexts — the session key is never sent, and you never see it here either. Can you
recover real bytes of the second message using nothing but XOR and a guess about the first?
Session A's ciphertext bodies (this is all an eavesdropper ever sees on the
wire — note: real AESGCM.encrypt() appends a 16-byte auth tag after this; this
sim omits it so the XOR below stays readable, but a real proof script must slice it off
first):
What you compute (the session key is never read):
Recovered fragment, both sessions