3 ms·
Thank you for digging into the code. This is why we are going open source. The encryption you are referring to is for encrypting a list of keys for your local n
by twknotes 7y ago
Thank you for digging into the code. This is why we are going open source. The encryption you are referring to is for encrypting a list of keys for your local notes storage, which is not exactly part of the end-to-end encrypted syncing. Since you have got this far, could you please have a look at:
https://github.com/twinkle-labs/twinkle-notes/blob/8ad7d9d0b544f4027ec1c7fa16d4780ee7695a2f/site-lisp/lib/space-storage.l#L264 https://github.com/twinkle-labs/twinkle-notes/blob/8ad7d9d0b...
> They must be unpredictable
I am wondering if that is necessary, because the hacker can't perform those attacks without the user's actively using the app at the same time. From what I learned, the attacking process requires the presence of key somewhere. If the attacker can get on user's device while one is using it, then it's almost a hopeless situation. Please educate me if I am wrong.
- CiPHPerCoder 7y ago> > They must be unpredictable > I am wondering if that is necessary, Yes, it is necessary. The IND security of Cipher Block Chaining (CBC) depends entirely on the IV being from a cryptographically secure random generator. CBC mode requires unique and random IVs. CTR mode requires unique IVs (but can be predictable). That's why we call the CTR input a nonce (number to be used once) and the CBC input an IV (initialization vector). Since they have different security requirements, we refer to them differently. Unfortunately, some cryptography libraries just name the parameter IV.
- metalliqaz 7y agoIs that distinction between nonce and IV held everywhere in the crypto community? For example, rfc8439 which defines the ChaCha-Poly AEAD does not require an unpredictable input nonce, and indeed calls it a "nonce", but many of the common implementations I've seen use "initialization vector" instead.
- CiPHPerCoder 7y agoLoosely. The majority have given up on the public understanding of nuances and just phone it in with "just don't write crypto". Because AES-CTR and ChaCha both refer to it as a nonce, and CBC calls it an initialization vector, the IV/nonce distinction does matter. But if you misuse the terms folks will know what you meant to say. Just don't mix it up when it comes time to implement.
- LookOutItsABot 7y agoPlease don't ever stop this behavior. I'm just learning much of this in an applicable way and people like you make this not just easier but possible for those of us learning with little outside help. The father I go down this rabbit hole the more I learn security should be like a religion of security (only one without dogma). Thanks.