7 ms·
Fair enough. I do note that the very blog you linked mentions that there are two 1Password formats: 1. The "Agile Keychain Format" (versions 2 and 3, which lac
by sdrapkin 11y ago
Fair enough. I do note that the very blog you linked mentions that there are two 1Password formats:
1. The "Agile Keychain Format" (versions 2 and 3, which lack integrity).
2. The "Cloud Keychain Format" (versions 4+, which have integrity).
You didn't specify which version you use & like.
I also note that the 1Password team had been selling security software which was not designed well - see (1) above. And it's not like HMAC wasn't invented when 1Pass got started.
Mr. Goldberg learns as he goes. There is nothing wrong with that. Or is there - when it comes to selling security software? Rhetorical question for all to ponder...
- tptacek 11y agoIf there was a password storage tool designed from the jump by a full-time cryptographic engineer, that'd be the one I'd talk about. Let me know if you find one?
- phlo 11y agoPassword Safe [1] was designed by Bruce Schneier, that could fit the bill. It seems to have done quite well in the paper cited by xenophonf in [2], too. [1] http://passwordsafe.sourceforge.net/ http://passwordsafe.sourceforge.net/ [2] https://news.ycombinator.com/item?id=9727522 https://news.ycombinator.com/item?id=9727522
- tptacek 11y agoLooking the C++ code for this project, this appears to be unauthenticated TwoFish in ECB mode. (I thought, no, no way is this actually ECB mode, maybe they just did the XOR'ing for CBC mode outside the TwoFish class, but no: they appear to pad blocks explicitly to block boundaries and then ECB them.) I looked for a total of 4 minutes, so if someone wants to correct me...
- pwg 11y agoYou need to look at the PasswordSafe file format. It can be found here (among other places): http://sourceforge.net/p/passwordsafe/git-code/ci/333dd9f23a3bdee81786750a760699e7dc865102/tree/docs/formatV3.txt http://sourceforge.net/p/passwordsafe/git-code/ci/333dd9f23a... ECB mode is only used for the internal keys. The database records are encrypted in CBC mode, and there is an integrity authenticator HMAC as well. However, the format was designed in the days when Mac-then-encrypt was considered proper. So the authentication HMAC is over the plaintext prior to encrypting.
- tptacek 11y agoYes, @tehjh on Twitter pointed this out. The CBC code is in Util.cpp, _readcbc; it appears to be length-delimited instead of padded, so there's probably another error oracle in the decoding of the length/type block. Also: in PWSfileV3.cpp, are they HMAC'ing the IV? This is interesting; we might be able to make an exercise out of it.
- eridius 11y agoJust to note, in the 1Password 4 Cloud Keychain design page[1], he specifically says > When the Agile Keychain format was developed, chosen ciphertext attacks (CCA) were seen as theoretical. Furthermore the primary threat to 1Password users was thought to be from an attacker stealing the data once and pursuing an off-line attack. It did not anticipate an attacker who could tamper with user data that would be subsequently processed by the legitimate owner. > CCAs are no longer just theoretical, and we also see (and encourage) widespread storage of 1Password data in “the cloud” for syncing. Thus data integrity needs to be addressed in our new design. It would have been great if the Agile keychain format included integrity, but hindsight is 20/20. [1]: https://learn2.agilebits.com/1Password4/Security/keychain-design.html https://learn2.agilebits.com/1Password4/Security/keychain-de...
- sdrapkin 11y agoI don't buy this "explanation" for the following reason: Even if they could not anticipate an attacker tampering with user data, surely they should've been able to anticipate filesystem corruption? Let's not pretend that MACs and secure integrity checks were a modern marvel just because CCA attacks were seen as theoretical back then.
- eridius 11y agoThe Agile Keychain format has a field called "contentsHash" (which looks to contain 32 bits of data). I'm assuming that's some sort of hash (perhaps crc32) of the encrypted contents, used to protect against corruption (but not against malicious attackers).
- tptacek 11y agoCan you help me understand what your fundamental argument is here? It seems pretty straightforward that the old, unauthenticated format is bad. Clearly, they didn't take crypto design very seriously when they shipped a product based on it. Is there some deeper subtext here? Whatever that subtext might be: it's especially weird coming from you, since you're the author of the story at the top of this thread, about a current version of KeePass that uses unauthenticated encryption. The EtM CBC+HMAC crypto design we're talking about for 1Password is years old.