4 ms·
BTSync continues to be a very interesting project but I remain concerned about how vulnerable the shared secret is to bruit-force attack. I'm not clear what th
by dotBen 13y ago
BTSync continues to be a very interesting project but I remain concerned about how vulnerable the shared secret is to bruit-force attack.
I'm not clear what there is to stop someone iterating through all combinations (especially as many will use dictionary-based secrets) to discover shares. Additionally, the master server BitTorrent run to broker the connections presumably also has all of the shared secrets and is vulnerable to attack.
I'm really excited about BTSync and have been proud to be in the early beta program but these security issues don't appear to be addressed.
- akama 13y agoI would not believe that the central server has all of the shared secrets. One possible solution is to hash the shared secret and send it to the central server. When someone wants to connect, just hash the key given and send it to the central server. You would get back a list of peers and then connect to them using encryption. The only problem is possible brute forcing of hashes. There are probably other ways of doing it.
- dotBen 13y agoYes, I hope they hash the secrets (and I guess someone could monitor the network traffic from the client to tell). Also, if someone did have the master list of hashed secrets, they might still be able to manipulate their own client to send the hashed secret back to the server and gain access. Being closed source, it's hard to know what the potential vectors are (granted, Dropbox is also closed source).
- akama 13y agoYou are correct that it's hard to judge security when the application is closed source. However the in the model we are suggesting, having the hashed secret would not be sufficient to get access to the files. Although you could use it to find client's IP addresses you would not be able to connect with it. The reason being that the secret key would be the base of any encryption between clients.
- andrewcooke 13y agoi don't understand. the faq says the secret is a generated 20 byte sequence. if we assume it's random then that's 160 bits, which is too expensive to brute force if it's used for a symmetric key (and it sounds like it is). and i don't see how dictionary attacks are relevant since it's a machine generated random chunk, not a small set of dictionary words. so can you clarify what you're worried about?
- giulianob 13y agoBTW, you can set the secret to a much larger value than the default. This should make even brute forcing very unlikely.