4 ms·
That line isn't used in anything sensitive.
by magikarp 13y ago
That line isn't used in anything sensitive.
- oinksoft 13y agoThe JsDoc for the function where var cnonce = MD5.hexdigest("" + (Cryptocat.random() * 1234567890)); occurs is /** PrivateFunction: _sasl_challenge1_cb * _Private_ handler for DIGEST-MD5 SASL authentication. * * Parameters: * (XMLElement) elem - The challenge stanza. * * Returns: * false to remove the handler. */ which is only called by /** PrivateFunction: _connect_cb * _Private_ handler for initial connection request. * * This handler is used to process the initial connection request * response from the BOSH server. It is used to set up authentication * handlers and start the authentication process. * * SASL authentication will be attempted if available, otherwise * the code will fall back to legacy authentication. * * Parameters: * (Strophe.Request) req - The current request. */ Now, I might be nuts, but unless the documentation is incorrect, this appears to be a "sensitive" application. To make sure I'm not just going on innuendo, I read into SASL authentication a bit ... seems `cnonce' is pretty important: A unique, encoded value that is generated by the client for each challenge response, and that is used to avoid chosen plaintext attacks, provides some message integrity protection, and provides mutual authentication. This authentication is provided mutually in that the server proves it knows the user’s secret information and not in that the server proves its identity. The nonce must be specified if a QOP directive is sent. Am I dead wrong, or are you hand-waving to defend your product?
- amouat 13y agoI notice they've continued their defense in an update to the blog post: "One more small note: Much has been said about a line of code in our XMPP library that supposedly is a sign of bad practice — this line is not used for anything security-sensitive. It is not a security weakness. It came as part of the third-party XMPP library that Cryptocat uses."