Currently, the IV is fixed. It currently uses the same value as the key, which is not a valid practice for AES encryption. This is is vulnerability allows the cryptography to be broken