7 ms·
Please remember that just because tptacek likes and uses something, do not mean that it has great security. The PDF linked below states that there is zero inte
by sdrapkin 11y ago
Please remember that just because tptacek likes and uses something, do not mean that it has great security.
The PDF linked below states that there is zero integrity in 1Password file format.
I happen to like and use KeePass, but that is not a secure-software guarantee.
- tptacek 11y agoI agree with your first sentence. But, regarding the rest of your comment: We use Encrypt-then-MAC authenticated encryption everywhere we use encryption. The MAC is HMAC-SHA256 and encryption is AES-CBC using 256-bit keys. Key derivation is uses PBKDF2-HMAC-SHA512. More detail about these choices will be presented in the relevant sections on key derivation and item encryption. https://blog.agilebits.com/2013/03/06/you-have-secrets-we-dont-why-our-data-format-is-public/ https://blog.agilebits.com/2013/03/06/you-have-secrets-we-do... Members of the 1Password team are vocal participants in the ongoing conversation about secure software and cryptography. For instance, Jeffrey Goldberg frequently gets involved in discussions of crypto vulnerabilities on Twitter. I don't have a formal recommendation to offer you regarding their team, but I can offer the same "I've talked to these people and feel like they know what they're doing" vibe that Schneier tried to offer for BestCrypt. Anyways: that's one of the reasons I like 1Password.
- sdrapkin 11y agoFair enough. I do note that the very blog you linked mentions that there are two 1Password formats: 1. The "Agile Keychain Format" (versions 2 and 3, which lack integrity). 2. The "Cloud Keychain Format" (versions 4+, which have integrity). You didn't specify which version you use & like. I also note that the 1Password team had been selling security software which was not designed well - see (1) above. And it's not like HMAC wasn't invented when 1Pass got started. Mr. Goldberg learns as he goes. There is nothing wrong with that. Or is there - when it comes to selling security software? Rhetorical question for all to ponder...
- tptacek 11y agoIf there was a password storage tool designed from the jump by a full-time cryptographic engineer, that'd be the one I'd talk about. Let me know if you find one?
- phlo 11y agoPassword Safe [1] was designed by Bruce Schneier, that could fit the bill. It seems to have done quite well in the paper cited by xenophonf in [2], too. [1] http://passwordsafe.sourceforge.net/ http://passwordsafe.sourceforge.net/ [2] https://news.ycombinator.com/item?id=9727522 https://news.ycombinator.com/item?id=9727522
- tptacek 11y agoLooking the C++ code for this project, this appears to be unauthenticated TwoFish in ECB mode. (I thought, no, no way is this actually ECB mode, maybe they just did the XOR'ing for CBC mode outside the TwoFish class, but no: they appear to pad blocks explicitly to block boundaries and then ECB them.) I looked for a total of 4 minutes, so if someone wants to correct me...
- pwg 11y agoYou need to look at the PasswordSafe file format. It can be found here (among other places): http://sourceforge.net/p/passwordsafe/git-code/ci/333dd9f23a3bdee81786750a760699e7dc865102/tree/docs/formatV3.txt http://sourceforge.net/p/passwordsafe/git-code/ci/333dd9f23a... ECB mode is only used for the internal keys. The database records are encrypted in CBC mode, and there is an integrity authenticator HMAC as well. However, the format was designed in the days when Mac-then-encrypt was considered proper. So the authentication HMAC is over the plaintext prior to encrypting.
- tptacek 11y agoYes, @tehjh on Twitter pointed this out. The CBC code is in Util.cpp, _readcbc; it appears to be length-delimited instead of padded, so there's probably another error oracle in the decoding of the length/type block. Also: in PWSfileV3.cpp, are they HMAC'ing the IV? This is interesting; we might be able to make an exercise out of it.
- newman314 11y agoI like and use 1Password too. But maybe someone smarter than I can explain what Goldberg is trying to say re 1Password and the paper "On the Security of Password Manager Database Formats" [1] [1] https://discussions.agilebits.com/discussion/comment/127847/#Comment_127847 https://discussions.agilebits.com/discussion/comment/127847/... One thing, I never liked about the 1Password file format was it's insistence on leaving certain fields unencrypted in order to allow the app to search using those fields. I've pushed for a "high security" preference option were all fields are encrypted to not avail. I'm willing to trade off the search convenience but that's a choice that Agilebits should allow me to make.
- tptacek 11y agoI don't know. I skimmed Gasti & Rasmussen 2012, and reread Goldberg's comment; unfortunately, I also just skimmed the source for for PasswordSafe V3, the "only one" that achieved "MAL-CDBA"; it appears to be cryptographically unsound (MAC-then-encrypt of an idiosyncratic AES-CBC).
- pvg 11y agoTheir newer format 'opvault' claims to address it as well as authentication - you're probably best off just googling 'opvault' for the various forum and blog posts about it. You can enable opvault in almost all the platform/sync combinations if you download the current v5 beta.
- newman314 11y agoEverything I've found so far says that opvault is still buggy. I didn't think v5 was still in beta as I've been happily using 1Password 5.