6 ms·
I took a quick look at the crypto design here, and it is deeply flawed. Please don't use this. The key exchange is simply an XOR of the pre-shared key with the
by axoltl 2y ago
I took a quick look at the crypto design here, and it is deeply flawed. Please don't use this.
The key exchange is simply an XOR of the pre-shared key with the session key instead of a proper key wrapping, there's no chaining mode specified for the AES encryption as far as I can see and perhaps most critically none of the data is authenticated.
A great example of "don't roll your own crypto".
- issafram 2y agoYea I was considering getting rid of Wireguard for this /s
- buro9 2y agoThe rest of the ideas seem valid, it's a shame to have the project undermined by the crypto. Is there no website of canonical examples of good crypto that can be shown to the author, so that they may trivially have good crypto?
- HL33tibCe7 2y agoGood crypto is hard. It’s extremely easy to make very subtle mistakes that completely undermine a cryptographic protocol’s security. Ultimately protocols like this need to be designed by someone with extensive experience in cryptography, then reviewed and tested by many similar people, before they can be considered safe to use.
- arghwhat 2y agoI honestly don’t think it has any interesting ideas. It doesn’t seem any easier than a WireGuard tunnel. The way for a non-cryptographer to make good crypto is to not write any crypto and rely on standard setups like TLS. Even chaining standard algorithms together can be dangerous.
- orphea 2y agoPerhaps libsodium? A library with selected crypto primitives and functions that is harder to misuse.
- kevin_nisbet 2y agoMaybe a noise implementation? http://www.noiseprotocol.org/ http://www.noiseprotocol.org/ Iirc this is what wireguard is based on and wireguard would be a great project to learn the crypto choices from.
- HL33tibCe7 2y agoIt’s puzzling to me that they didn’t just use TLS.
- kkfx 2y agoThe idea seems a "quick support" kind of connectivity, meaning you just pass a string to be paste in a terminal and you are on the same "LAN", for such casual temporary usage I'm not much concerned, but... Where the "linker" service to be self-hosted on demand?
- mojyack 2y agoYou can use my server written in the README. the peer-linker's source can be found here https://github.com/mojyack/peer-linker https://github.com/mojyack/peer-linker The documentation is not ready yet, but I will write it soon.
- kkfx 2y agoThanks, but please in general publish always the complete package, relaying on third party service it's like not being FLOSS because the potential user still do not have at his/her own hand the complete infra so can't really operate, extend, improve alone and give back the results. The current service epidemic have almost killed free IT in general and we must stop it.
- mojyack 2y agoAuthor here. Thanks for pointing out the security issue! I'm a novice in cryptography, and the encryption used in this program was just an idea I came up with. I'm going to learn a bit more, but if you have any good ideas for improvements, could you let me know?
- alphager 2y agoI can fully recommend this book by one of the TLS 1.3 contributors; it doesn't require a cryptographer background and serves as an extremely good starting point: https://www.manning.com/books/real-world-cryptography?a_aid=Realworldcrypto&a_bid=ad500e09 https://www.manning.com/books/real-world-cryptography?a_aid=...
- axoltl 2y agoCryptography is tricky to get right. There are a ton of subtle ways things can go wrong! I think the first thing to realize is your problem has probably been solved by someone else, so you can use off-the-shelf solutions. TLS has a pre-shared symmetric key option: https://en.wikipedia.org/wiki/TLS-PSK https://en.wikipedia.org/wiki/TLS-PSK for example. Second, I think it's important to know how crypto fails in order to use it properly. https://www.cryptopals.com https://www.cryptopals.com has a bunch of challenges that walk you through breaking a crypto implementation.
- endofreach 2y agoOT: i stumbled upon your name a few times here on HN now through nice & interesting comments. I am not ready yet, but are you for hire to help a startup with your expertise in the near future? How could I contact you?
- axoltl 2y agoAlways happy to talk! I've put a temporary email in my profile.