SPECK Decrypt
Decrypt SPECK64/128 ciphertext produced by SPECK Encrypt.
Decrypt SPECK64/128 ciphertext in your browser. CBC mode, PBKDF2 key derivation. Free, offline, runs client-side. Read more Show less
What is SPECK decryption?
SPECK decryption reverses the encryption performed by SPECK Encrypt. It reads a single Base64 (or hex) string containing the random salt, random IV, and ciphertext, derives the SPECK key from your password using PBKDF2-SHA-256, and decrypts in CBC mode.
SPECK64/128 is an NSA-designed lightweight block cipher with a 64-bit block and a 128-bit key. It is not a replacement for AES in general-purpose use - see the encrypt page for the full discussion.
How to use
Paste the Base64 or hex ciphertext, enter the same password that was used to encrypt it, and press Decrypt. The output is the original plaintext.
Why does decryption fail?
Three common causes:
Wrong password. The derived key will be different, and CBC decryption will produce garbage bytes. The PKCS#7 padding check at the end of decryption catches almost all wrong-password cases and reports "Invalid padding".
Truncated ciphertext. CBC ciphertext must be a multiple of 8 bytes. If copy-paste lost any characters, decryption fails with a length error.
Wrong ciphertext format. Base64 and hex produce different byte sequences from the same string. Choose the format that matches how the ciphertext was encoded.
FAQ
Can I tell if the password is correct without decrypting?
Not with SPECK alone. CBC with PKCS#7 padding catches most wrong passwords because the padding check fails. But there is roughly a 1 in 256 chance that a wrong key produces valid-looking padding by coincidence, in which case you get garbage plaintext instead of an error. For verifiable decryption, use AES-GCM or ChaCha20-Poly1305, which include authentication tags.
Does the byte order matter?
Yes. This tool uses little-endian byte order, matching the NSA reference implementation. Some other SPECK implementations use big-endian, in which case ciphertext is not interchangeable.
Can I decrypt OpenSSL or GnuPG output?
No. Neither OpenSSL nor GnuPG supports SPECK by default. This tool only decrypts data produced by SPECK Encrypt on this site, or by another implementation using the same CBC and byte-order conventions.
What happens if I get the wrong variant?
SPECK has many variants (block sizes 32, 48, 64, 96, 128 bits and key sizes 64-256 bits). This tool implements SPECK64/128 only. Ciphertext from a different variant will decrypt to garbage or fail padding validation.
Is it safe to paste ciphertext into a browser tool?
This tool runs entirely client-side. Nothing is uploaded. But you should always verify that claim by opening your browser's Network tab and confirming no requests are sent after page load. Do not paste production secrets into a site you did not audit.
Command line equivalent
# No standard CLI tool ships SPECK.
# Node with the simon-speck npm package
npm i simon-speck
node -e '
const speck = require("simon-speck");
const key = Buffer.from("...16 bytes hex...", "hex");
const ct = Buffer.from("...ciphertext hex...", "hex");
const cipher = new speck.Speck(key, speck.SPECK_64_128);
console.log(cipher.decrypt(ct).toString());
'