11 ms·
CryptDown – Client-side AES-encrypted Markdown pastes
- Fastidious 11y agoInteresting! Other than JS, what else runs on the backend?
- ikkez 11y agobackend is driven by PHP Fat-Free Framework (http://fatfreeframework.com http://fatfreeframework.com), as stated in the info window ;)
- Fastidious 11y agoDuh! I missed that one, amongst so many JS ones. My mistake. Thanks!
- paul-sh 11y agoYou shouldn't have minified the code, let people check what's going on.
- ikkez 11y agogood point. I reverted the minification, but will put it back once I published the whole code on github. thx
- Fastidious 11y agoGoing to open source it?
- nacs 11y agoAuthor has open sourced it now: https://github.com/ikkez/CryptDown https://github.com/ikkez/CryptDown
- paul-sh 11y agoIkkez, you use hash == HMAC-SHA256(CT, SHA256(password)) to check if the password is valid. You should replace the "SHA256(password)" part here with a strong password-based key derivation function (PBKDF2, scrypt, bcrypt) with a decent number of iterations. SHA256 is blazing fast. While this is a good thing for a hash function in general, it is not for a key derivation. PBKDF2, scrypt, bcrypt and others are slow by design to make an attack much harder.
- deleted 11y ago[deleted]
- sarciszewski 11y agoAre they comparing MACs with a strategy that fails as soon as a byte differs? Hah. http://blog.astrumfutura.com/2010/10/nanosecond-scale-remote-timing-attacks-on-php-applications-time-to-take-them-seriously/ http://blog.astrumfutura.com/2010/10/nanosecond-scale-remote...
- paul-sh 11y agoThe site compares MACs in the client's browser, so a timing attack is not really an issue here.
- sarciszewski 11y agoIt's indicative of bad engineering.
- ikkez 11y agoI think it does not matter that much here, as this hash is just used for checking the message integrity. This hash is build from the encrypted doc + the hashed password. if you are about to brute force the HMAC function, you would just get a SHA hash back. It would make more sense to try to break the message directly. I got this trick from http://stackoverflow.com/a/23190781/2038179 http://stackoverflow.com/a/23190781/2038179
- 11y ago
- fabulist 11y agoNice. I have a CLI for a similar site (kopy.io); do you mind if I add support for your site as well? My project is here: github.com/xmnr/kopycat It boasts a single user right now, so it shouldn't burden you with traffic too much.
- jknz 11y agoThe WYSIWYG editor is really nice. I'm wondering if it is home-made or if it comes from a library?
- someone13 11y agoThis appears to be https://github.com/daviferreira/medium-editor https://github.com/daviferreira/medium-editor
- sarciszewski 11y agoIf you're not shipping your cryptography in a browser extension, npm module, etc. then you might as well not implement the cryptography features. http://matasano.com/articles/javascript-cryptography/ http://matasano.com/articles/javascript-cryptography/
- zokier 11y agoSee also: Google End-To-End https://github.com/google/end-to-end https://github.com/google/end-to-end
- sarciszewski 11y ago"End-To-End is a Chrome extension..." Your argument is invalid.
- lewisl9029 11y agoThe WebCrypto API is meant to solve this but many aspects of it are not quite ready for production yet. I'd personally love to see JS crypto libraries like CryptoJS, SJCL and Forge start implementing polyfills for WebCrypto. Even just using the getRandomValues method (which seems to be fairly stable across all modern browsers) for their PRNG implementations would result in a much more theoretically sound crypto library. http://www.w3.org/TR/WebCryptoAPI/ http://www.w3.org/TR/WebCryptoAPI/ https://github.com/digitalbazaar/forge https://github.com/digitalbazaar/forge https://github.com/bitwiseshiftleft/sjcl https://github.com/bitwiseshiftleft/sjcl https://code.google.com/p/crypto-js/ https://code.google.com/p/crypto-js/
- tracker1 11y agoI'd like to see more async implementations of crypto for JS, breaking work up with setTimeout/setImmediate so that they don't kill the browser... Lately, I'm more inclinded to first reach for the browserify polyfills, and use the node crypto api.
- ikeboy 11y agoA quick search turns up http://0bin.net/ http://0bin.net/, https://cryptbin.com/ https://cryptbin.com/, https://cryptobin.org https://cryptobin.org, https://defuse.ca/pastebin.htm https://defuse.ca/pastebin.htm, https://paste.sh https://paste.sh, http://sebsauvage.net/paste/ http://sebsauvage.net/paste/, and https://pastee.org/about https://pastee.org/about. Is there anything new in your implementation, or is this just "me too"?
- Someone1234 11y agoNone of those have a WYSIWYG editor for markdown, and no markdown renderer. So I'd call those the USP rather than the encryption in and of itself.
- ikeboy 11y agohttps://cryptbin.com/ https://cryptbin.com/ does markdown, but not WYSIWYG.
- ikkez 11y agowell maybe I just have the NIH-Syndrom ;) this is a microservice. Anyone can re-build it in some days. I just wanted that fancy Medium Editor, Markdown and encryption, and didn't found it yet.
- ikeboy 11y agohttps://cryptbin.com/ https://cryptbin.com/ renders markdown.
- Fastidious 11y agoIt is not open source. Will that make a difference?
- ikkez 11y agoIt's open source now: https://github.com/ikkez/CryptDown https://github.com/ikkez/CryptDown feel free to add your own ideas and improvements.
- dsacco 11y agoHey, cool project. As another poster in this thread mentioned, you have a cross-site scripting vulnerability because you don't properly sanitize the decrypted user input. I might work on this if I get a little time later today, but in case I don't, here are a few resources for you: http://stackoverflow.com/questions/3129899/what-are-the-common-defenses-against-xss http://stackoverflow.com/questions/3129899/what-are-the-comm... https://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%29_Prevention_Cheat_Sheet https://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%... The good news is that PHP is so widespread that there are really great tutorials and libraries for sanitizing user input and preventing cross-site scripting. Good luck!
- ikkez 11y agoshould be fixed now.
- nialo 11y agoIs there a written description of the protocol used between the client and server anywhere?
- gose1 11y agohttps://cryptdown.eu/view/23mz2dmpdq5co https://cryptdown.eu/view/23mz2dmpdq5co - password: lolz and this is why we don't like crypto in the browser...
- dsacco 11y agoThis is a cross-site scripting vulnerability, yes, but client-side crypto does not necessitate cross-site scripting. This implementation just so happens to not protect against it properly. There are legitimate arguments against client-side cryptography; this is not one of them.
- jacksingleton 11y agoThe argument is that implementing crypto within an application that is designed to download and execute untrusted code from untrusted servers and has an extremely large attack service [1] is a difficult if not dangerous task. [1] your browser
- deleted 11y ago[deleted]
- kragen 11y agoWhile that may be true, that’s a different class of vulnerabilities that doesn’t include XSS.
- adventured 11y agoYou should have a prominent "clear" action button, to wipe the pre-loaded example content with a click. I tried clicking on "Create New" in the upper right hoping that would generate that effect, but it just resets it all back. I think a 'clear content' button would be especially nice for mobile.
- Buge 11y ago>Nobody can help you when you loose an encryption password *lose