4 ms·
I don't see any key being stored client side. So you must be deriving the key from my password? If that's the case, then my attack would be: * Loop through a
by h8trswana8 13y ago
I don't see any key being stored client side. So you must be deriving the key from my password?
If that's the case, then my attack would be:
* Loop through a list of common passwords.
* Derive keys from those passwords.
* See if any decrypted results return an ASCII-like result.
- absherwin 13y agoThat would work for a sufficiently broad definition of common. You're welcome to try. The challenge is that it'll take a long time unless you have incredibly fast hardware or are very good at guessing.
- h8trswana8 13y agoEh, whatever key derivation algorithm you are using is running in a browser, and isn't throwing any long-running JS exceptions. And I didn't see my browser block. So it can't be that expensive. From an academic viewpoint, it's not really strong encryption if your AES key is derived from a password. Your key space is limited to ASCII characters, and 99% of users will not choose a strong password. So from my perspective, if you sent me a DB dump, I could read almost everything.
- absherwin 13y agoEmail me and I'll send you the DB dump. You can brute force it . I don't think it's as trivial as you suspect but I'd love for you to prove me wrong.
- h8trswana8 13y agoIt's trivial to brute force for anyone who has a weak password. More importantly, it's trivial for an adversary who cares. If I'm encrypting a note containing state secrets to send to a foreign intelligence officer, the NSA has the technology (and more importantly, the resources) to brute force their way in. And if your password is too complex to crack (read: a 256-bit key), you probably can't remember it either, which means you have to write it down somewhere; so an adversary who cares would find an outside channel (subpoena, hack your personal computer) to determine your key. What is your key derivation algorithm? PBKDF2?
- absherwin 13y agoThe key is derived by PBKDF2 with 1000 iterations. For weaker passwords, I suspect a couple of order of magnitude strengthening would be required. Your point about weak passwords holds in both ordinary clients and in the browser. It's just a matter of degree. There are plenty of sufficiently strong passwords that are memorable. Since the degree of weakness tolerable is logarithmically proportional to the hashing time and JS is usually within an order of magnitude of native code, the additional entropy required is small given equivalent hashing time.