4 ms·
Yeah, cryptography libraries in general are a pain to use and typically require a lot of seemingly arcane configuration and confusing (to the novice) setup. I
by jsdalton 14y ago
Yeah, cryptography libraries in general are a pain to use and typically require a lot of seemingly arcane configuration and confusing (to the novice) setup.
I wrote this library recently (primarily to scratch an itch on another project), which really does nothing more than pass sane defaults to PyCrypto and eliminate crypto jargon:
https://github.com/jsdalton/secrets.py https://github.com/jsdalton/secrets.py
Honestly I think it took more time to wrap my head around the simple use cases than it did to implement this wrapper once I did.
- sneak 14y agoYour key setup leaves a whole lot to be desired. (There's a very real reason that PBKDF2 exists.) Bad crypto libs like this are the EXACT reason that things like NaCl and KeyCzar were created. Please don't do things like this. PS: It's also not clear if you're doing the HMAC check in a time-invariant manner: https://github.com/jsdalton/secrets.py/blob/master/secrets/cryptors.py#L101 https://github.com/jsdalton/secrets.py/blob/master/secrets/c... See: http://codahale.com/a-lesson-in-timing-attacks/ http://codahale.com/a-lesson-in-timing-attacks/
- tptacek 14y agoStop using this and start using Sodium, which is more secure than your wrapper library in significant ways that illustrate why people shouldn't think of this stuff as "jargon" that they can just write wrappers for; for instance: * It generates encryption keys insecurely instead of using a cryptographically secure KDF * It leaks timing information on the MAC comparison * It makes verification of messages optional; verification should never be optional (in your case, when verification is disabled, I think you have the CBC padding oracle vulnerability)
- jsdalton 14y agoThanks for your comments and recommendation. Your points (and my own failings here) illustrate why libraries like Sodium (which was not on my radar a few weeks ago) are a good thing. As an ordinary developer, I just want to use a library like PyCrypto in a safe manner. When I described the language as "jargon" I did not mean to be dismissive of it, but rather to say that libraries like PyCrypto force you to make decisions about terms that are nothing more than jargon to a non-expert -- when really what a non-expert needs is an extremely simple API which makes those decisions on your behalf in a safe manner. Thanks again and these are humbling lessons to learn.
- tptacek 14y agoYou seem smart and like someone who enjoys this stuff, so if you want a much more fun lesson (or, uh, 40+ of them), drop a line to sean AT matasano DOT com and he'll send you a bunch of exercises that'll teach you how to exploit this stuff.
- X-Istence 14y agoAre any of those lessons public, or semi-public? I am very interested in stuff like that as I am working on crypto systems for a gov't project.
- tptacek 14y agoOpen invite! Send mail to sean, he'll get you started. We're not publishing them and we'll ask you not to circulate them, but instead to let anyone you know who wants to see them to just mail sean.