16 ms·
Hardbin: secure encrypted pastebin
- Veratyr 9y agoIt's very interesting but the title seems a little hyperbolic as there are numerous caveats (from the "About" section): - "Note that the security benefits of hardbin only apply when accessing it over a local (or otherwise trusted) gateway. If you access it over a gateway that you do not control, then the security model degrades to be equivalent to that of traditional encrypted pastebins." - "The content will need to be pinned to make sure it stays around for long term (the same as any content stored in IPFS)." (though this doesn't impact the merits of its encryption) - "You need to make very sure to use a known-good version of the code when creating pastes, as it would be trivial to create a malicious version that looks identical. The best thing to do is write down the hash the first time you use it, and always use the same hash. If you want to upgrade to a new version of the software, you'll need to update your hash." - "I don't recommend using hardbin for highly critical stuff as the code has not been thoroughly audited by anyone but me." The last is perhaps the most worrying thing.
- jjguy 9y agoThese are all standard security concerns. Anyone who brings you something similar and does not have a long list like this is in marketing or sales.
- avaer 9y agoIf these are all standard security concerns, doesn't that make this a standard security pastebin? I think the point is that it's an extraordinary claim with unextraordinary evidence.
- true_religion 9y agoDoes anyone remember when the phrase "extraordinary claims require extraordinary evidence" was used regards to truly extraordinary claims? Like room-temperature superconductors. Or cold fusion. Or that aliens were responsible for the birth of human civilization? This is not an extra-ordinary claim. This is the claim of "I made secure software, and I reckon it's pretty good" wrapped up in the extremely ordinary common English-language hyperbole of calling something 'the best' when there is no way to know if it is, or prove it one way or the other.
- bradknowles 9y agoHowever, the use of hyperbole transforms the claim into an extraordinary one. That is, unless you consider hyperbole to now be standard, in which case we have to likewise transform the original material being quoted. Otherwise we're comparing apples to super duper hyper bestest-ever oranges.
- true_religion 9y agoYep, I consider the use of hyperbole to be a standard colloquialism in this case, not a claim that they did an in-depth experimental study of pastebins and have compiled a report for peer review.
- tangent128 9y agoThe vanilla "secure pastebin" is simply an insecure pastebin served over HTTPS. Better, actually-trying-to-be-secure pastebin implementations will encrypt the data with JS before sending it to the server, and later decrypt it with a key that's embedded in the link's URL fragment (which the server never sees). The security evolution here is that both the ciphertext and the code for the webpage to decrypt it are stored on IPFS, which is a content-addressed filesystem. Thus, so long as you access pastes through a trusted (ie, local) IPFS note, the hardbin server operator can't insert code on the webpage after-the-fact to exfiltrate the key or plaintext back to them.
- nickpsecurity 9y agoOr just knocking out risk areas using proven solutions in ways similar to past within parameters the cryptographers state instead of new, fancy stuff. Plus one for a memory safe language low-level enough for preventing leaks. Works more often than the new, fancy stuff.
- dang 9y agoWe took "the world's most" out of the title above.
- nickpsecurity 9y agoIt's still inaccurate with word secure in there. That's a more widespread problem, though. ;)
- eeZah7Ux 9y agoFor how long is publicly available, encrypted data going to resist bruteforce decryption? 30 years perhaps? Usually the "millions of years" estimate ignores the Moore's law. Your data might be secure when is encrypted and never leaves your network.
- DonbunEf7 9y agoWhy not just use Tahoe-LAFS? Then you don't have to trust the server to get the security guarantee!
- tangent128 9y agoIf you access hardbin through your own, local, IPFS gateway, then you don't have to trust a third-party server. I assume if you used a third-party Tahoe-LAFS gateway instead of running your own, you would have the same security risks.
- ams6110 9y agoWhy not just gpg-encrypt and ascii-armor your text for the recipient(s), and put it in an ordinary pastebin?
- nickpsecurity 9y agoExactly. Some kind of proven cryptosystem implemented with great UI on untrusted, online storage. Options to do it over various transports with HTTPS a default that most users can tolerate. This one does all this fancy stuff which has so much complexity in its trusted computing base (TCB) that it's likely to get smashed somehow. That's assuming the protocols and interfaces are correct which is often not true. Plus, the "world's most secure" would probably use HSM's at some point with real ones at server and smartcards w/ open standards at user side. I know a guy working to commercialize stuff like that. Stuff running on a vanilla stack w/ unvetted code and non-tamper-resistant hardware isn't most secure anything.
- imron 9y agoEase of use for both encrypters and decrypters?
- tptacek 9y agoThe world's most secure encrypted pastebin, guaranteed What could possibly go right?
- imron 9y ago*not guaranteed
- airza 9y agofinally, i can combine the security of the browser with the convenience of seeding torrents!
- nickpsecurity 9y agoGreat phrasing lol...
- middleclick 9y agoThe footnote says: (* this is not a guarantee). OK, I guess...
- anc84 9y agoSomeone might make a snarky remark on HN.
- segmondy 9y agogood for storing passwords. /s
- CiPHPerCoder 9y agohttps://github.com/jes/hardbin/issues/1 https://github.com/jes/hardbin/issues/1 You don't exactly need clairvoyance to predict this outcome.
- dsacco 9y agoThere really needs to be an awareness campaign for developers to let them know encryption != authentication != integrity.
- sametmax 9y agoTime to add IFPS to 0bin.net then ?
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- jstanley 9y agoHi all, I made this. The reason it is described as "the world's most secure" is because both the code and the data are served from IPFS. IPFS is a content-addressable storage system, so as long as you access it over an IPFS gateway you trust (running one locally is the best way), you know the code and data haven't been meddled with. It degrades to the same security model as ordinary encrypted pastebins when accessed over a gateway you don't trust (e.g. the hardbin.com public gateway). This article (was on HN a couple of weeks ago) gives a good overview of IPFS: https://ipfs.io/blog/24-uncensorable-wikipedia/ https://ipfs.io/blog/24-uncensorable-wikipedia/ And you can learn how to set up a local IPFS node here (it's super duper easy - copy binary into /usr/local/bin, ???, profit): https://ipfs.io/docs/getting-started/ https://ipfs.io/docs/getting-started/ So, please, don't knock it before you understand it :) EDIT: Although I did try to explain it thoroughly in the About section, I do take responsibility for not making it easy enough to understand. IPFS is pretty new technology, and presents a very different set of assumptions compared to traditional web apps. If you didn't understand it at first but you do understand it now, please let me know what the key piece of information was that made it "click" so that I can put more emphasis on that next time.
- dsmithatx 9y agoIf you add a check box to make it a "one time secret" this would be very useful for sharing passwords.
- dangerface 9y agoIf your security can be degraded to the same security model as everyone else then you have the same security model as everyone else. Your paste bin is cool and unique no need to lie about it.
- jstanley 9y agoIt can't "be degraded" by others. You decide whether you want to degrade it or not.
- garrettr_ 9y agoA quick look at the source code shows the generate_key() function [0] to be insecure. It generates 32 random bytes (good, that's what you need for an AES-256 key), but then it uses those random bytes to sample from a distribution which only has 62 characters. This significantly reduces the security of the key, from 256 bits of entropy to ~190 bits (log2(62^32)). And that would be in the best case, if it were sampling uniformly from the distribution - it is not. I recommend reading Section 9.7 of Cryptography Engineering [1] to understand why choosing random elements from a set is harder than it seems. A good example of a similar bug is the nasty bug in Cryptocat's PRNG from 2013 [2]. I assume this step was done so the AES key could be included in the URL fragment, since a set of random bytes may not be url safe. I recommend feeding the random bytes of the key directly into the underlying cryptographic functions, and using a urlsafe encoding at a higher level when necessary. Also, it appears you are using AES [3], a block cipher, but I cannot figure out what block cipher mode you are using. I'll have to dig into the CryptoJS code a little more to see what it defaults to, but I have a sinking feeling that it's ECB, which is completely insecure. Dan Boneh's Crypto I course on Coursera is a good way to learn the basics of block cipher modes. [0]: https://github.com/jes/hardbin/blob/c77c2d7eb93586e0e009ea4b390b75fa3d7c750f/js/hardbin.js#L13-L25 https://github.com/jes/hardbin/blob/c77c2d7eb93586e0e009ea4b... [1]: https://www.amazon.com/Cryptography-Engineering-Principles-Practical-Applications/dp/0470474246 https://www.amazon.com/Cryptography-Engineering-Principles-P... [2]: https://nakedsecurity.sophos.com/2013/07/09/anatomy-of-a-pseudorandom-number-generator-visualising-cryptocats-buggy-prng/ https://nakedsecurity.sophos.com/2013/07/09/anatomy-of-a-pse... [3]: https://github.com/jes/hardbin/blob/c77c2d7eb93586e0e009ea4b390b75fa3d7c750f/js/hardbin.js#L5-L7 https://github.com/jes/hardbin/blob/c77c2d7eb93586e0e009ea4b...
- pizza 9y agoPastebins tend to get caught up fast in very dodgy/shady/even illegal content.. just a heads up
- agumonkey 9y agoAny quick way to minimize nasty uploads ?
- mirimir 9y agoWell, encryption helps with deniability, no?
- arianvanp 9y agoBut he is not hosting anything. It's a self-hosted peer-to-peer pastebin storage system
- elbrian 9y agoThis is very interesting. Could you elaborate or possibly share any resources you may have / know of on the matter?
- deleted 9y ago[deleted]
- qguv 9y agoFor a simpler secure pastebin, try https://sptpb.pw https://sptpb.pw.
- unsignedint 9y agoAlso another alternative. https://privatebin.info https://privatebin.info
- lousken 9y agoand another one https://safepaste.org https://safepaste.org (although currently suffers from bug)
- mproud 9y agoI was always a fan of paste.ee, but totally welcome more encrypted paste web sites.