5 ms·
Wait, how does the receiver find the sender, just via the passphrase? How does that work? Is there a relay server and if so how do sender and reciever know who
by codeulike 6y ago
Wait, how does the receiver find the sender, just via the passphrase? How does that work?
Is there a relay server and if so how do sender and reciever know who the relay is?
- bscphil 6y agoGood question. My impression of it is that it's a little janky at present, compared to Magic Wormhole. Yes - there's a relay server, but you don't have to trust the relay. (As of changes made in March - before that Croc sent the key in the clear to the relay.) The first three characters of the passphrase are used to establish a shared channel between the sender and receiver, and the rest of the key is used to do a PAKE, which is a secure method for key exchange. The default passphrase is only three words long, and according to another comment the wordlist is only 1626 words, so you should assume the first word of the keyphrase is entirely blown and useless for securing you from the relay. So that makes the space effectively 1626^2 = 2.6M passwords. To MITM you the relay would have to guess which of those passwords is correct. Magic Wormhole works a bit differently. IIRC it dynamically requests a channel from the server which is prepended to the passphrase as a number. This seems a bit more resilient to me, as the birthday problem suggests it's quite likely two people will end up with the same channel just by bad luck with Croc. Edit: indeed, a test forcing similar passwords beginning with the same three characters completely screws Croc up. I can do "croc send -c 'xyz blahblahblah' filename" on multiple computers without error, but croc receives go to the first channel even if they have the wrong password. Edit: There are only ~900 different three letter word beginnings in the wordlist, so you'd only need to claim that many channels on the server to make it unusable for anyone who lets Croc pick passwords, and occasional collisions between users are certain. Lol that should probably be fixed.
- qrv3w 6y ago> "croc send -c 'xyz blahblahblah' filename" on multiple computers without error That seemed to be a bug and is fixed now. After two parties enter a channel it should give you a "room is full" response. > Magic Wormhole works a bit differently. IIRC it dynamically requests a channel from the server which is prepended to the passphrase as a number. This seems a bit more resilient to me, as the birthday problem suggests it's quite likely two people will end up with the same channel just by bad luck with Croc....There are only ~900 different three letter word beginnings in the wordlist, so you'd only need to claim that many channels on the server to make it unusable for anyone who lets Croc pick passwords, and occasional collisions between users are certain. Lol that should probably be fixed. I think wormhole uses only 99 channels [1] so it is also susceptible to a DOS attack. But generally, collisions in channels can occur but are probably pretty rare because I don't have enough people using croc simultaneously to collide. Importantly - colliding channels doesn't undermine security because you have to have the whole passphrase to successfully perform PAKE. But, when you say it should probably be fixed, you refer to mitigating a DOS attack? [1]: https://github.com/warner/magic-wormhole/issues/107 https://github.com/warner/magic-wormhole/issues/107
- bscphil 6y ago> That seemed to be a bug and is fixed now. That's likely the case, it looks like I had an old version installed in Termux. But in any event that's just a matter of getting an intelligible error message, and not fixing the underlying problem. > I think wormhole uses only 99 channels [1] so it is also susceptible to a DOS attack. In that case I'd certainly have the same concern. > But generally, collisions in channels can occur but are probably pretty rare because I don't have enough people using croc simultaneously to collide. I disagree. Suppose you only average 2 users at a time. In this case ~1/630 connections will randomly collide, just by chance, which means that some people have certainly experienced this already. IMO that's too high, and in any case the relay code certainly shouldn't be written to only support <10 channels. (Note that the number of collisions will actually be higher than my back of the envelope math suggests, because some 3 character prefixes will be more common than others since you're using English words.) Importantly - Wormhole doesn't have this problem, even though it technically has a lower channel limit, because it allocates channels dynamically instead of having the client pick them. IMO it's also pretty weird to take the channel ID from the beginning of the passphrase. This takes away any entropy you'd otherwise get from the first word, since you're using a wordlist, which means the effective size of the secret used for PAKE is only about 1600^2. If you're okay with that, just use the entire word. It seems pretty low to me. But yes I would like to see more work done to mitigate extremely easy DOS attacks, given that this seems like the most obvious vulnerability to these relay-managed PAKE approaches.
- qrv3w 6y agoI'm confused about why you wrote "relay code shouldn't be written to only support <10 channels" as any three character combination is a channel? You mention wormhole doesn't have a problem with colliding channels, but that it requires assigning a channel from the relay. To me this is a trade-off. If wormhole can't connect to a relay, wormhole can't assign a channel and won't work. Whereas, in croc, if you can't connect to the relay it will still work over LAN since the client chooses the channel. I appreciate this discussion, there's a discussion on Github about this now. [1] Would you mind moving this discussion there? [1]: https://github.com/schollz/croc/issues/261 https://github.com/schollz/croc/issues/261
- als0 6y ago> As of changes made in March - before that Croc sent the key in the clear to the relay That doesn't instill me with confidence about its development
- Fiahil 6y agoYes, right here: https://github.com/schollz/croc#self-host-relay https://github.com/schollz/croc#self-host-relay
- qrv3w 6y agoThe receiver and sender find each other using the first three characters of the passphrase to establish a channel to communicate. Once in the channel they perform PAKE which will allow both parties to establish a secure key from the entire passphrase OR it will alert both parties that the passphrases differ and will break the channel (PAKE only works if the passphrase is the same, even if they made it to the same channel). The sender and receiver know who the relay is beforehand. That is they either use the default relay (baked into the croc binary) or specify another relay.