9 ms·
Should have used the WebCrypto API instead of the crypto-js npm package. https://developer.mozilla.org/en-US/docs/Web/API/Web_Crypto_API https://developer.mozil
by realPubkey 4y ago
Should have used the WebCrypto API instead of the crypto-js npm package.
https://developer.mozilla.org/en-US/docs/Web/API/Web_Crypto_API https://developer.mozilla.org/en-US/docs/Web/API/Web_Crypto_...
- iamben 4y agoI spent some time Googling this about 6 months ago. Lots of tutorials on Crypto-js, not so many (and almost zero "here's a super simple implementation") for WebCrypto API. I can understand if this is a hobby project why you'd lean into one rather than the other, I probably would have done the same.
- cgb223 4y agoSounds like a golden opportunity for someone with a developer blog to make useful content
- trusz 4y agoNot going to pretend that I know what the most of the stuff mean, or if it is even safe enough, but I've followed the MDN articles and put together this TypeScript snippet [1]. Maybe somebody could comment on it? Also sorry for the long link. Is there any accepted way to post a shorted URL? Edit: added a corrected version [2] [1]: https://www.typescriptlang.org/play?#code/DYUwLgBAbiDGYHsBOEC8EDuBLAdgEwQwDpYkBPAB0SIHNwAlAQ3wQFsA1R4AVxAGcAFDhAYIAVVxgAHAEEkSRmQEBGAGwBKdQG4AUHsZ8yOWBABm3Y2CwIcEEMfJUAKgAt7AETiOwAvl-AAsvx8jHQAXHxgSLg0ADQQFAZ8GMh4YRCR0Tg0EOrpAApIbFh+ADwA2pkx8TjcrABGIEgAugB8EADeehA9EAD0fTq9-X0QhSAUQ70DUz2wNpEQANYgZGgQjBiMWJB0wgpgIADSqwBiRaz5SSlIeAKJfMmp6t3Tg8MDEACiDpRWNjRZiMgfMcIt7KQ-iA8EFHqEQOtNttIBDvLCQnQBCsyPE-KRAsF4doQQsUb9Dnh3IwwIx1sJRBIcNI5AolKioTDCXRtCMIKUALQZex4CBgFwlV49Ab8mX8oEzD6jTyQqjy95vUGLPBeDmIrY7CDalVgdHwrGreLsqjQ03cklgyBG7zQvXIw06qi2kDmnF2cnQqk0l7DTWOj0UwO09D08SSWTyRQCJ0c4kh0nu43QpwgAAekHQoJgSDALMUACFuKZTE1EABlKIxJPhgPUxgvSW8zUIUBEYAIGgCABEyudIrwrfSg4gAGoM8GNQtuyAiNr6twBwBycruL5lsQAcWaEA38Q62Mtv2tnLhdAvkIjrfiyavT+blMfGdH2bzAF9ckCkHAbgkFscpnwpb8wDvcgHxpXt7BoMVmh0H99EMYwzAseBrFsPYmmpY4zguK5HhuO4HieW4IgbbI8jGC4ShAUoAGFvAQE4yFaLoIFDCAsFYChkApEjKJFdAkQNbAWGIY0ECIPhuHqMAe34wTiw4gQgWGQcFAwQdYi03pCxresshoJwEFLMgKyrJp7muZ4DOGYYOkHHBGFYEBB0nfIyyOdxTgAJkHH8nOcnpTC4Px4k+AU7DzBR4EYepQAAfkMnpykHbVohgDjB2Q4ZiXtRYQmAfMIEHMUETKyASlFcU+AgBQWFYDIaJoQcSsgbFXUk3ACBktj5MU5TlxyrA8tWTTwp6bjZu09zPO8yrfP8oL9Iy5zB1qlbjOLUyYgsqybOrJBfC4MB1DChaekHHZ8P+MEVuUAAGd73pu27BxcAwXBWwdawACRkflAoAVlULqFtCrbVKE6ERLIr6XK2xaPK8ycZC+Wt+X3ZiAk227ekHUBsjFF7AqkLbYYWyLgGirasqtMB9Mq8CCqBYrhkAsBgNsbEULQowTHMSwcL9Y0vR9dJWL+diLSFfETS5EB0iqWjOgAoCQMwAbCBIYaFKUnsWYEDolrVyrsdx-HCfiSb0hgeBkFC5ZFf2sBDuyY6E2syszt8fwVZvEBNF0VCdAMEXMPFmxPz+aXsVltiOOgjkvXSE6A6adQtZ5nXbCkwbDflkaTfG8NzctrGcbxgm2cd6A4EQJA3fPSXRy9YlI7F7D48973zMsv3TrszJqLMujGWZP3896KBGBQCEEByukRAgSCfnmHKBFTXpef5yXV6aIgV+1Xwoh7nQ+6enibCLEtR5z4sECHgQ11spB0hn+NWTyDWOR5o9EXigI0J8UDRg3pBZUEChzcDAKYfkUhBz7x6IfXW4CcorjgCfD+L9r7CwwrfCWrBtg4D3sA++DoIDICwDQXAXAvTrEHAAYkNAgWAdR7A0jvjQbgWBgDamALgBE0MjLpjxLzFhrA1iIAoErXm4i5jpnKKYRhwAvS4iwAALxAAAeVMNvUckYjziX1GSY0rgPBVzoQw9ymjVa4mDvOFRYIlxECSDWAQdiNHMNQAEswfjVauOoXwDxfYBxUOGKwPgNAwg7V0fwWhphDStjZltXxDj0hZKYareC5MXDxC2izaE6skmGOMRySMxSFoHDVr4CpRjLywUYH0XJjjQ4FMQi4UJP4XiRy7D2WAoAl57x0GQ3Ae8gA https://www.typescriptlang.org/play?#code/DYUwLgBAbiDGYHsBOE... [2]: https://www.typescriptlang.org/play?#code/FAiGGcE8DsGMAIBmBXOAXAlge2vApnAE6QAOaAKgBYEAiesxZAFMPG-OPYXmgLJ7hwoAOZ4AXODSEM0YQBp4rdiQjgA7lkIATMRykz5SthgBuugKoy0ADgCChQqEhyjHUABs0E-bJfAAlLoACoRYALYYnAA8ANqS0r7w0MhhAEZ4hAC6AHzwAN4g7PAA9MWupfAheCTlZUWwOJLwANZ4kPAAvPCgaqAYaPCi0BmgaHgA0m0AYqFhQaoa2kwqgotaCkKe-oXspbXwAKJEpJg4ta4N0E0EDCd4WvyCInid3b39+Mdkj0KiTK3ODhcHg-Z4KUz+ADcF0aAxuxDGWhoo1Ar2GanglmgNnsjkgTHhdweAl+eChJWK8CiAFogdAtPA0JRIjs2KVqRzqecihU6LcyNzdsVLk0tFwia8en0BmL+XwSc9-m0FISyPdQaJtvVYfBZYxEZL3jLxd8FX8ASrjojkWhQOCTFr2CLjXL7jbUV10ZirHYHE4mHqiVCYVcXfr7uQ8AAPAZdS4mDJoXFOABCyEQiETWAAyj5hAGTdaUdtWRT4CKsO48AA6dxYfMAIj54YZWhRugb8AA1Lr6I62cLGpWa2LUsh8wByGI0A4p8wAcUy8AnCjyFs+ruJT1EltuRdtCkDavWvc37sPhYj0bQAF94P34Nw0MhCLgYkfEZGY7uEW6UbWCGEJlMmAG8wCgOAkFQWBTlwIYRjGSZIBmcJ5lWTQtGWBYMO8BJ5DcTxdHiAxAkqWZIjwKIAGF9SwJDsgKcsdQwMISE0RE0PUDDDWleA1BkLQsDUas5SwatwGQVI0CrasWLYwg0CQlgiiKBtHDUBsXBUp0cATBTczw8gsGTSA0wzDIsPQ7R-C07T8gbaBQDCPAGw7IIU3GGgpgAJgbG9bO0xAPE4BQKhpfAY0cGDQFSKsAH5XCKGIGzFaQEyQhsQKKYMQyaAEeI+fj6SEkTaPEyTpJHDJTAmNplLsxi7NUxznNc+AG3czyfM0xK7IbTY0Da+NEwMgwjJMszM0IJgBps3rtIbfoEOwK42oARgABi2raAqa9rKAgSg2obbMAAlbGpbyAFYADYG3m+B-IeuT2PuTi1l2opGr29qWpcjtbAObNqXnKjeB6n62AbKtZCZdbvOsB6nqaoL3BCh7ktVQaFBSwtMtcHKiifF9cABUDwJgBAUHQFaN31DU8CVSBdBok46OVIEGBBM1xD0PD7QsH0TP8fJXGJ18+IEkrRPKqSZKxpg8j+gGgZBsHNPgUx-JaDnhv0vNxr9Uz0ymmbgXlbcyWDMDgAgSmoJpnBT3pnmmZZ2ikJ-IkGd0CaTYyAXvWxX08RF77Hx4EnJeK4SZYkuWqrlRXlfawHgdB8H7W19csfVHnrZAamYNpvW0FG2RDbxSaLPiXCSMF4OTNFooTFAQgNywVK0TwDEvzQI4GlSphgyJyOJZuTuMmrCexRmqQC6L2CmOgPSkyN6uFJzPMmDHczCAbnEjcCYjZGb9hW-b2VJ-bz0e-gPu+WvpgG2QNBEGpawGxH9hxdwK-UurP-Rmu8poF2AIvWmjhiphAAGoeGQAIYeB8Q5OHDr-aOglY5lVEGgAASqAaBcD3AIPAEwL0WJD54iYGtG6-htg2wppBCBTswh9GgMPcOzp4CaAwMIGQHgGavAbAAYl1FgWAKQCC2iXsIZAGB3BincDIF491tShk5k+IRYR2hoCwCQDRPBVE6XUQmGCmhXhQMErA+BiDv5sC4QNIRTIXiOMiIyZk4BHwEKsXzAwYhOw9kseEIhJDh6li4TERA-D3AMw2BgAAXngAA8ogAeLZ3RLi6FKD4WMqC0ELEwHhfDHIxJ5hsc2ChTG6MIBsDwaAHwVhkqoRMhTpDFIETzToHQuhRJKQzBpQ4ZJ1nzOHIomBnK6BtDWaAQlh6hUpAAK2QE0XRQIXgYEQO4l4wzywHVkAIbhuBnGPl4UyB6YRwDCH8eABJBysCbLbLaDWD0inRNiS8tp0TdCvL6TzACsNKAKAernHQHBbkpLSUSc8igUZvLKQ9RwYwxAzXBakr4+5QDFB+R0y2-ygKUAfDeehIBGk1lgFWNuYTWEyGHkAA https://www.typescriptlang.org/play?#code/FAiGGcE8DsGMAIBmBX...
- tptacek 4y agoIf you call "encrypt" more than once in that code, you'll leak the authentication key. Every invocation of GCM encryption needs a unique nonce. Cryptography nerds will chastise you for using a random nonce (there theoretically isn't enough room in the GCM nonce space to safely encrypt large numbers of message with random nonces), but the alternative (using a counter) is even more hazardous. This problem motivates a lot of people to use other AEADs like XChapoly, which has an extended nonce space that safely admits random nonces. Isn't cryptography fun?
- trusz 4y agoOh yes! Thank you for the feedback. I've added a new version where the `iv` and the `salt` is random. Maybe a followup question: Because you need both the `iv` and `salt` to decrypt the message is it ok in an E2E scenario to send all three: `iv`, `salt` and the encrypted message?
- tptacek 4y agoI didn't look to see what "salt" means in your design, but the idiom for using GCM in message encryption is to send ciphertexts that take the form `nonce || ciphertext`, and to decrypt by reading the nonce off the front of the message.
- majou 4y agoFrom what I shallowly researched; GCM's nonce seems limited to 12 bytes by convention only. That nonce reuse is so fatal seems absurd to me. Would "salting" the key safely tackle the problem? Put explicitly; send <- nonce || salt || ciphertext recv -> decrypt(ciphertext, nonce, pbkdf(pass) || salt) [edit: apply salt outside of the kdf]
- tptacek 4y agoAs I remember it, the balance of the bytes in the AES block are used for the counter. At any rate, the convention is essentially universal.
- paulpauper 4y agoWhat is the major difference? Isn't crypto-js still secure?
- Xeoncross 4y agoOne is a Javascript package, the other is a browser library following a spec that is implemented by all the major browser companies. Web Crypto is faster and has many more devs working in the different implementations between all the companies and doesn't require any includes.
- lucideer 4y agoIt might be. Whereas the native lib should be. Just levels of trust. I'd happily use the former if the latter didn't exist.
- irrational 4y agoWhy use a library (thus incurring the need for the user to download more JS) instead of using what is already in their browser?
- tptacek 4y agoI don't know what "secure" means. Is their implementation of OFB correct? Probably. But using OFB mode is itself a problem. From what I can see, crypto-js implements no authenticated modes, and exposes all sorts of crufty old things nobody should be using. The parent comment suggesting WebCrypto is correct in this case. Avoid crypto-js.
- deleted 4y ago[deleted]
- dividuum 4y agoMine does: https://github.com/dividuum/html-vault/ https://github.com/dividuum/html-vault/
- fifafu 4y agoWebCrypto only works in secure contexts (https), which is a significant limitation for some use cases. But I agree it should be an option.