7 ms·
Saltstack: Changing RSA public exponent from 1 to 65537
- willvarfar 13y ago> These represent the security issues found in the audit performed by Ronald Volgers So this bug was found and fixed by a proper professional audit. Neat.
- StavrosK 13y agoProfessional audit results: "Umm, you're sending your key in plaintext".
- jgrahamc 13y agoThere ought to be a way for people to get 'writing some crypto code' out of their system without it being a part of a real project. A sort of play area where you can have a go but not harm anything and people can point out your errors. Every time I write something that involves some crypto I get absolutely terrified of what I'm likely to mess up. For that reason I almost always use an existing system or protocol. For example, on one of the projects I'm working on at CloudFlare we needed a secure connection across the Internet so I went with TLS 1.2. For another I needed the same thing but with better authentication: TLS 1.2 with client and server certificates. If I need to exchange encrypted messages in some store and forward style I'd likely use PGP. And then for another project I needed to actually get something someone else had encrypted with RSA and decrypt it. Nightmare. If you find yourself calling low-level crypto APIs start to worry.
- daeken 13y agoThe Matasano crypto challenges ( http://www.matasano.com/articles/crypto-challenges/ http://www.matasano.com/articles/crypto-challenges/ ) are a great way to do this. Not by implementing crypto, but by breaking crypto in ways that will scare you away from ever implementing crypto.
- Nursie 13y agoI recommend Coursera's Crypto 1 course - it walks you through the internals of a lot of the crypto stuff, hammers "Don't do it yourself!" into you and there are programming challenges that involve breaking crypto constructions, finding hash collisions etc etc. I'm really hoping crypto 2 actually starts in about 10 days as it seems to have been put back a lot. --edit-- Just to sell it further, it also goes into padding oracles, timing attacks and a variety of clever stuff to show you just how easy it is to screw up :)
- StavrosK 13y agoOh, man, that course contained so much of "Do you see any problems with this construction? No? It can't possibly be vulnerable to anything, you say? Boom, here's how to break it completely". My mind was blown on every course video.
- cantos 13y agoSadly, Crypto 2 seems to be delayed to Oct 15 now.
- Nursie 13y agoAwww, dammit. I was looking forward to that. I only checked a couple of weeks ago.
- RyanZAG 13y ago"Every time I write something that involves some crypto I get absolutely terrified of what I'm likely to mess up." Good! " For that reason I almost always use an existing system or protocol." Excellent! If only every was like you we wouldn't have these problems. The key to understanding this is to understand that cryptography is not 'writing some crypto code'. No part of cryptography has anything to do with the code. Cryptography is about math - feel free to do some cryptography math and work on a mathematical algorithm. Once you have a perfect algorithm that has been peer reviewed, then you can transcribe that mathematical algorithm into code. Failing to understand the math first means you have already failed and simply should not have even begun. Cryptography: math first, code later. Failure to follow this sequence means you will be ridiculed and any excuse is simply not good enough.
- jdiez17 13y agoThank you for being the voice of reason. It's so easy to get confused, too, because "crypto code" is indistinguishable from "other code", but the implications are much greater. You don't need to peer review a IRC library, but you _need_ to peer review cryptography. That's just how it is, and if I had to highlight one sentence from your comment it would be "Failing to understand the math first means you have already failed and simply should not have even begun." I wish people would understand this instead of thinking trial and error works for cryptography. I mean, heck, most of us learned to code through trial and error, and I can understand why people think they can learn cryptography the same way, but that is not true, and a very toxic mindset.
- maggit 13y agoI agree in general, but you are painting with too broad strokes here: > No part of cryptography has anything to do with the code. There have been successful attacks against cryptography based on attacking the implementation. For example if two code paths take different time to execute, it is possible that this leaks information. This is another reason why you should use a well honed library implementation of cryptography, for example OpenSSL. This does of course not imply that the crypto–the maths of it–is broken. One just needs to be aware that it is not, in fact, sufficient to implement the maths correctly.
- jbert 13y ago> If I need to exchange encrypted messages in some store and forward style I'd likely use PGP. Do you or others have any recommendations for cross-platform library code (at least OSX, Windows, Android, Linux, Windows 8) for this purpose? I may have understood incorrectly, but I thought that using gpg from code required launching a sub-process (e.g. via gpgme). That makes me very nervous from a library point of view, perhaps I'm wrong to be nervous. Is the answer still "use PGP/GPG" or is there somewhere else I could look to avoid home-made cryptosystem here?
- jgrahamc 13y agoGPG actually has a library with all the crytographic primitives in it called libcrypt: https://en.wikipedia.org/wiki/Libgcrypt https://en.wikipedia.org/wiki/Libgcrypt If you want the PGP-level stuff then there's GPGME: http://www.gnupg.org/related_software/gpgme/index.en.html http://www.gnupg.org/related_software/gpgme/index.en.html
- jbert 13y agoThanks for that. But afaics, libgcrypt seems to be on a similar level of abstraction as the openssl lib? i.e. implementations of ciphers etc. I then fall into the mistake of http://www.cs.berkeley.edu/~daw/teaching/cs261-f12/misc/if.html http://www.cs.berkeley.edu/~daw/teaching/cs261-f12/misc/if.h... I think? [linking to berkely.edu because the page seems to have gone from matasano.com?] And I think GPGME is a lib which "under the hood" spawns a command-line gpg process? http://www.gnupg.org/faq/GnuPG-FAQ.html#cant-we-have-a-gpg-library http://www.gnupg.org/faq/GnuPG-FAQ.html#cant-we-have-a-gpg-l... At the moment it looks like my choice is between implementing a cryptosystem on top of crypto primitives (from openssl or libcrypt) or seeing if I can get away with shipping a lib which spawns child processes via gpgme.
- aidenn0 13y agoIronically, there is a high-level crypto library with sane defaults that is pronounced "salt" (it's spelled NaCl though)
- 23david 13y agoI agree with your points here. I think a major issue is the lack of understanding of best-practices with regards to security. So we tend to rely on the security of systems that aren't battle-proven. But even battle-proven solutions still have vulnerabilities, so we need to rely on multiple layers of security. For me at least, this reinforces the lesson to put systems as much as possible behind multiple layers of security such as firewalls and VPN. And I should be careful to architect salt systems in a hub/spoke topology using salt-master and syndics. And encrypt any traffic from the salt-master to groups of servers using ssh tunneling. Looks like pyzmq now supports ssh tunneling, so maybe this would work: http://zeromq.github.io/pyzmq/ssh.html http://zeromq.github.io/pyzmq/ssh.html
- deleted 13y ago[deleted]
- reidrac 13y agoThere's an entry on the release notes [1], the changelog, etc; but unless I'm missing it, looks like there's not really proper management of security issues (same thing for the recent crypto.cat bug). May be I'm old-school but when a project goes over certain size and there's no prominent "security" section (as important as downloads, IMHO), that's a red flag for me. This is the way you do it: - http://httpd.apache.org/security_report.html http://httpd.apache.org/security_report.html - http://openssh.org/security.html http://openssh.org/security.html - http://nginx.org/en/security_advisories.html http://nginx.org/en/security_advisories.html All projects doing sensible tasks have a security history. Don't hide it, make it public and accessible to your users. [1]: http://docs.saltstack.com/topics/releases/0.15.1.html#rsa-key-generation-fault http://docs.saltstack.com/topics/releases/0.15.1.html#rsa-ke...
- throwaway125 13y agoDo you have any links to the crypto.cat bug?
- agwa 13y agohttp://tobtu.com/decryptocat.php http://tobtu.com/decryptocat.php https://blog.crypto.cat/2013/07/new-critical-vulnerability-in-cryptocat-details/ https://blog.crypto.cat/2013/07/new-critical-vulnerability-i... https://news.ycombinator.com/item?id=5989707 https://news.ycombinator.com/item?id=5989707
- norswap 13y agoThis shows crypto is much too hard. You can configure a bunch of things, but half the choices you can make (key length, exponent, etc...) will render your encryption worthless. I shouldn't have to know about the chinese remainder theorem to use crypto properly.
- Nursie 13y ago>> This shows crypto is much too hard. Crypto is hard, and you shouldn't really be making these choices. >> I shouldn't have to know about the chinese remainder theorem to use crypto properly. Then stay out of it. Choose a library/framework that is popular, well tested and high level enough that you don't have to make these choices.
- norswap 13y agoAny pointers? And I don't something that will take care of everything for me, but simply a pair of encrypt / decrypt functions.
- Nursie 13y agoThe usual ones to recommend here are KeyCzar and NaCl (apparently pronounced salt, not related to saltstack AFAICT). NaCl in particular provides simple Public/Private and Symmetric modes. The Authenticated Encryption Symmetric mode here is good - http://nacl.cr.yp.to/secretbox.html http://nacl.cr.yp.to/secretbox.html
- kevinpet 13y agoHis complaint is that crypto is to hard to use. This is a valid complaint and "don't do it" isn't a valid solution. Too many "libraries" consist only of implementations of the crypto algorithms, but don't give any help with the proper use.
- Nursie 13y ago>> His complaint is that crypto is to hard to use. Yes, and if you're going to use low level constructions he's right, and that will never change. >> This is a valid complaint and "don't do it" isn't a valid solution. Except that's not what I said, I said find a higher level library. When he asked I gave examples. >> Too many "libraries" consist only of implementations of the crypto algorithms, but don't give any help with the proper use. Then these may be the wrong libraries to use to secure your application. Great libs to poke around in the lower levels for a variety of other purposes of course.
- simias 13y agoCan someone comment on how broken it was to use 1 as exponent? Is it just a theoretical concern or does it mean the crypto could have been easily broken (as we saw with cryptocat yesterday)? I'm asking because they seem to treat it like a minor issue: It's of course questionable whether 1 (not a prime) was a good choice for the exponent to begin with, but it's hardly necessary to lose faith over this.
- daeken 13y agoOn a scale of 1-10, it was about a 15 on the broken scale. As explained in the comments on the patch, a public exponent of 1 means a private exponent of 1 (it's the inverse). This makes it completely, trivially broken.
- ams6110 13y agoSo why don't the crypto libs at least throw a warning that "what you're doing is nonsensical" if not just reject an exponent of 1 outright? We hammer on people not to invent their own crypto, yet here someone is, using the RSA lib, and still doing it wrong.
- MichaelSalib 13y agoThey're not using a crypto library, they implemented RSA from scratch.
- paulgb 13y agoThey're using a library (M2Crypto) to generate the an RSA key at least, so ams6110's point stands.
- MichaelSalib 13y agoOh. Sorry about that. I should have looked at the diff more carefully.
- 13y ago
- raverbashing 13y agoWhat's more striking is that the first person that comes all "you're an idiot and I'm a crypto expert" gives a wrong suggestion Item 4 here: https://en.wikipedia.org/wiki/RSA_(algorithm)#Key_generation https://en.wikipedia.org/wiki/RSA_(algorithm)#Key_generation
- ig1 13y agoIt's amazing that this got through, you don't need to be a crypto expert for this to jump out as wrong. Anyone with undergrad number theory or crypto should easily be able to realize that using 1 is crazy.
- gizmo686 13y agoI don't think you necessarily need special training. A value of 1 should immediately make you wonder why you are providing it as in input at all. Interestingly, even a small prime, like 3, has no known vulnerability (but it allows other vulnerabilities to be attacked faster)
- ipmb 13y agoHere's a ticket to track for following the state of crypto in Saltstack, https://github.com/saltstack/salt/issues/5913 https://github.com/saltstack/salt/issues/5913. It includes a lot of thoughts from the project founder on how to handle it.