4 ms·
I think you use this to validate the password, not to check the integrity of the message. And an attacker gets a password as a result of brute-forcing, not a ha
by paul-sh 11y ago
I think you use this to validate the password, not to check the integrity of the message. And an attacker gets a password as a result of brute-forcing, not a hash. Look at this snippet in pseudocode:
// Get the hash and the encrypted text from the encrypted data
hash = substing(encryptedData, 0, 64);
encryptedText = substing(encryptedData, 64);
foreach password in PasswordDictionary {
if hash == HMAC(encryptedText, SHA256(password)) {
print "Password found: " + password;
// Decrypt the message
print "Message: " + AESDecrypt(encryptedText, password);
}
}
The loop will run fast, and you get a clear-text password as a result, which can decrypt the message. If you replace SHA256(password) with PBKDF2(password, 20000) the loop becomes insanely slower.
- tracker1 11y agothat assumes an async pbkdf2 implementation for the browser... most browser implementations for crypto I've seen are synchronous, though I'm uncertain today, I haven't checked for a couple years now. In the case of synchronous, most browser based variants will kill the script before it completes... you could use workers, but that won't work for ie<=9 [1]. Which may or may not be an option here. As it stands, it would be a nice options. I really like the markdown editor implementation, will look at how they are using medium-editor... I'm working on a similar implementation and was considering going side-by-side, but this actually looks/works better. I did write a sanitization utility[2] for such inputs, but hadn't yet completed the editor. [1] http://caniuse.com/#feat=webworkers http://caniuse.com/#feat=webworkers [2] https://www.npmjs.com/package/cc-text-utils https://www.npmjs.com/package/cc-text-utils