5 ms·
Yeah, the 16-bit "wormhole code" means that each active MitM attack has a 2^-16 chance of success, and a 1-(2^-16) chance of causing a broken connection. The er
by lotharrr 11y ago
Yeah, the 16-bit "wormhole code" means that each active MitM attack has a 2^-16 chance of success, and a 1-(2^-16) chance of causing a broken connection. The error message you get (which also happens if someone simply mistypes the code) is:
% wormhole receive-text
Enter receive-text wormhole code: 9-babylon-typo
ERROR:
Key confirmation failed. Either you typed the code wrong, or a would-be
man-in-the-middle attacker guessed incorrectly. You could try again,
giving both you and the attacker another chance.
On average, you should expect to see 32 thousand failures before there's a 50/50 chance of a successful MitM attack. If your transfer attempt fails 10 times in a row, you're probably under a persistent attack, and you should stop using this tool.
Since failed attacks are so visible, I decided that 16 bits was a good tradeoff. Note that you can make it longer: "wormhole --code-length=4" uses 4 words (32 bits), etc. There's also a --verify option that displays a full-strength SHA256 session key hash for comparison, after the PAKE exchange but before transferring any actual data. Finally, since the words are coming from a fixed list, there's tab-completion when you input the codes, which turns out to be really handy.
PAKE codes are single-use, and not subject to offline attacks, so I don't think 128 bits codes are necessary (it'd be a different story if they were hashed directly into encryption keys :-). Incidentally, magic-wormhole uses (my) "python-spake2" library, which implements SPAKE2 (http://www.di.ens.fr/~pointche/Documents/Papers/2005_rsa.pdf http://www.di.ens.fr/~pointche/Documents/Papers/2005_rsa.pdf) over the Ed25519 elliptic-curve group.
The magic-wormhole python package includes a library to use these codes in other tools: in the long run, I'm hoping to get PAKE more visibility as a "pair two computers together" primitive, and transferring SSH keys would be an awesome use case for that. Also, I'm planning to add a "--persistent" flag of some sort, which records the generated session key somewhere, indexed by a petname, so the second time you want to send someone a file, you just say "wormhole send-file --petname=bob", and you don't have to transcribe a wormhole code at all.