crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY] - #295

Merged
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation
Apr 30, 2021
Merged

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY]#295
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation

Conversation

@tarcieri

@tarcieritarcieri commented Apr 30, 2021

Copy link
Copy Markdown
Member

Previous versions of this crate did not derive a uniformly random key when used with the XChaCha20Poly1305 AEAD.

The implementation has been updated to use the HChaCha20 function for this purpose, however this change makes the Curve25519XChaCha20Poly1305 construction implemented by versions earlier than this commit incompatible.

This was an unfortunate oversight in what is otherwise a non-standard construction with no other known implementations to test against. Perhaps libsodium implements this construction and we could try to ensure compatibility there going forward.

The suggestion for any users of the previous implementation is to migrate all ciphertexts to the new construction, as the original construction was broken. Please open an issue if this actually impacts you and you would like help addressing the problem.

This issue likely deserves a RUSTSEC advisory.

cc @alxiong

Previous versions of this crate did not derive a uniformly random key
when used with the XChaCha20Poly1305 AEAD.
The implementation has been updated to use the HChaCha20 function for
this purpose, however this change makes the Curve25519XChaCha20Poly1305
construction implemented by versions earlier than this commit
incompatible.
This was an unfortunate oversight in what is otherwise a non-standard
construction with no other known implementations to test against.
Perhaps libsodium implements this construction and we could try to
ensure compatibility there going forward.
The suggestion for any users of the previous implementation is to
migrate all ciphertexts to the new construction, as the original
construction was broken. Please open an issue if this actually impacts
you and you would like help addressing the problem.
This issue likely deserves a RUSTSEC advisory.
@tarcieritarcieri added the bug Something isn't working label Apr 30, 2021
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

Merging #295 (e622712) into master (2604d2a) will increase coverage by 0.04%.
The diff coverage is 100.00%.

Impacted file tree graph

@@ Coverage Diff @@## master #295 +/- ##
==========================================
+ Coverage 84.43% 84.47% +0.04% 
==========================================
Files 31 31 Lines 1137 1140 +3 ==========================================
+ Hits 960 963 +3 
Misses 177 177 
Impacted FilesCoverage Δ
crypto_box/tests/lib.rs100.00% <ø> (ø)
crypto_box/src/lib.rs88.63% <100.00%> (+0.83%)⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 2604d2a...e622712. Read the comment docs.

@tarcieri
tarcieri merged commit 2d2e588 into masterApr 30, 2021
@tarcieri
tarcieri deleted the crypto_box/fix-xchacha20poly1305-key-derivation branch April 30, 2021 00:37
@tarcieritarcieri mentioned this pull request Apr 30, 2021
@tarcieri

Copy link
Copy Markdown
MemberAuthor

I was going to file a RUSTSEC advisory for this, but then I realized that this may not in fact be a security-critical issue.

Namely, the XChaCha20 construction performs a similar HChaCha20 derivation to derive the ChaCha20 key. In theory, this should produce a uniformly random ChaCha20 key.

The original NaCl crypto_box and its "Curve25519XSalsa20Poly1305" construction uses HSalsa20 twice however, so it is probably best to move forward with this construction as being closer to the XSalsa20-based equivalent, and perhaps there is a reason for the double-HSalsa20 cascade used in the original construction I'm not aware of.

FWIW, I have confirmed that we in theory implement the same construction as libsodium in crypto_box v0.6.0:

https://github.com/jedisct1/libsodium/blob/e1fa9cc/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305.c#L45-L51

I opened #303 to track adding test vectors to ensure that our implementation is compatible with libsodium's.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@codecov-commenter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY] - #295

Merged
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation
Apr 30, 2021
Merged

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY]#295
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation

Conversation

@tarcieri

@tarcieritarcieri commented Apr 30, 2021

Copy link
Copy Markdown
Member

Previous versions of this crate did not derive a uniformly random key when used with the XChaCha20Poly1305 AEAD.

The implementation has been updated to use the HChaCha20 function for this purpose, however this change makes the Curve25519XChaCha20Poly1305 construction implemented by versions earlier than this commit incompatible.

This was an unfortunate oversight in what is otherwise a non-standard construction with no other known implementations to test against. Perhaps libsodium implements this construction and we could try to ensure compatibility there going forward.

The suggestion for any users of the previous implementation is to migrate all ciphertexts to the new construction, as the original construction was broken. Please open an issue if this actually impacts you and you would like help addressing the problem.

This issue likely deserves a RUSTSEC advisory.

cc @alxiong

Previous versions of this crate did not derive a uniformly random key
when used with the XChaCha20Poly1305 AEAD.
The implementation has been updated to use the HChaCha20 function for
this purpose, however this change makes the Curve25519XChaCha20Poly1305
construction implemented by versions earlier than this commit
incompatible.
This was an unfortunate oversight in what is otherwise a non-standard
construction with no other known implementations to test against.
Perhaps libsodium implements this construction and we could try to
ensure compatibility there going forward.
The suggestion for any users of the previous implementation is to
migrate all ciphertexts to the new construction, as the original
construction was broken. Please open an issue if this actually impacts
you and you would like help addressing the problem.
This issue likely deserves a RUSTSEC advisory.
@tarcieritarcieri added the bug Something isn't working label Apr 30, 2021
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

Merging #295 (e622712) into master (2604d2a) will increase coverage by 0.04%.
The diff coverage is 100.00%.

Impacted file tree graph

@@ Coverage Diff @@## master #295 +/- ##
==========================================
+ Coverage 84.43% 84.47% +0.04% 
==========================================
Files 31 31 Lines 1137 1140 +3 ==========================================
+ Hits 960 963 +3 
Misses 177 177 
Impacted FilesCoverage Δ
crypto_box/tests/lib.rs100.00% <ø> (ø)
crypto_box/src/lib.rs88.63% <100.00%> (+0.83%)⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 2604d2a...e622712. Read the comment docs.

@tarcieri
tarcieri merged commit 2d2e588 into masterApr 30, 2021
@tarcieri
tarcieri deleted the crypto_box/fix-xchacha20poly1305-key-derivation branch April 30, 2021 00:37
@tarcieritarcieri mentioned this pull request Apr 30, 2021
@tarcieri

Copy link
Copy Markdown
MemberAuthor

I was going to file a RUSTSEC advisory for this, but then I realized that this may not in fact be a security-critical issue.

Namely, the XChaCha20 construction performs a similar HChaCha20 derivation to derive the ChaCha20 key. In theory, this should produce a uniformly random ChaCha20 key.

The original NaCl crypto_box and its "Curve25519XSalsa20Poly1305" construction uses HSalsa20 twice however, so it is probably best to move forward with this construction as being closer to the XSalsa20-based equivalent, and perhaps there is a reason for the double-HSalsa20 cascade used in the original construction I'm not aware of.

FWIW, I have confirmed that we in theory implement the same construction as libsodium in crypto_box v0.6.0:

https://github.com/jedisct1/libsodium/blob/e1fa9cc/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305.c#L45-L51

I opened #303 to track adding test vectors to ensure that our implementation is compatible with libsodium's.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@codecov-commenter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY] - #295

Merged
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation
Apr 30, 2021
Merged

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY]#295
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation

Conversation

@tarcieri

@tarcieritarcieri commented Apr 30, 2021

Copy link
Copy Markdown
Member

Previous versions of this crate did not derive a uniformly random key when used with the XChaCha20Poly1305 AEAD.

The implementation has been updated to use the HChaCha20 function for this purpose, however this change makes the Curve25519XChaCha20Poly1305 construction implemented by versions earlier than this commit incompatible.

This was an unfortunate oversight in what is otherwise a non-standard construction with no other known implementations to test against. Perhaps libsodium implements this construction and we could try to ensure compatibility there going forward.

The suggestion for any users of the previous implementation is to migrate all ciphertexts to the new construction, as the original construction was broken. Please open an issue if this actually impacts you and you would like help addressing the problem.

This issue likely deserves a RUSTSEC advisory.

cc @alxiong

Previous versions of this crate did not derive a uniformly random key
when used with the XChaCha20Poly1305 AEAD.
The implementation has been updated to use the HChaCha20 function for
this purpose, however this change makes the Curve25519XChaCha20Poly1305
construction implemented by versions earlier than this commit
incompatible.
This was an unfortunate oversight in what is otherwise a non-standard
construction with no other known implementations to test against.
Perhaps libsodium implements this construction and we could try to
ensure compatibility there going forward.
The suggestion for any users of the previous implementation is to
migrate all ciphertexts to the new construction, as the original
construction was broken. Please open an issue if this actually impacts
you and you would like help addressing the problem.
This issue likely deserves a RUSTSEC advisory.
@tarcieritarcieri added the bug Something isn't working label Apr 30, 2021
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

Merging #295 (e622712) into master (2604d2a) will increase coverage by 0.04%.
The diff coverage is 100.00%.

Impacted file tree graph

@@ Coverage Diff @@## master #295 +/- ##
==========================================
+ Coverage 84.43% 84.47% +0.04% 
==========================================
Files 31 31 Lines 1137 1140 +3 ==========================================
+ Hits 960 963 +3 
Misses 177 177 
Impacted FilesCoverage Δ
crypto_box/tests/lib.rs100.00% <ø> (ø)
crypto_box/src/lib.rs88.63% <100.00%> (+0.83%)⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 2604d2a...e622712. Read the comment docs.

@tarcieri
tarcieri merged commit 2d2e588 into masterApr 30, 2021
@tarcieri
tarcieri deleted the crypto_box/fix-xchacha20poly1305-key-derivation branch April 30, 2021 00:37
@tarcieritarcieri mentioned this pull request Apr 30, 2021
@tarcieri

Copy link
Copy Markdown
MemberAuthor

I was going to file a RUSTSEC advisory for this, but then I realized that this may not in fact be a security-critical issue.

Namely, the XChaCha20 construction performs a similar HChaCha20 derivation to derive the ChaCha20 key. In theory, this should produce a uniformly random ChaCha20 key.

The original NaCl crypto_box and its "Curve25519XSalsa20Poly1305" construction uses HSalsa20 twice however, so it is probably best to move forward with this construction as being closer to the XSalsa20-based equivalent, and perhaps there is a reason for the double-HSalsa20 cascade used in the original construction I'm not aware of.

FWIW, I have confirmed that we in theory implement the same construction as libsodium in crypto_box v0.6.0:

https://github.com/jedisct1/libsodium/blob/e1fa9cc/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305.c#L45-L51

I opened #303 to track adding test vectors to ensure that our implementation is compatible with libsodium's.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@codecov-commenter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY] - #295

Merged
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation
Apr 30, 2021
Merged

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY]#295
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation

Conversation

@tarcieri

@tarcieritarcieri commented Apr 30, 2021

Copy link
Copy Markdown
Member

Previous versions of this crate did not derive a uniformly random key when used with the XChaCha20Poly1305 AEAD.

The implementation has been updated to use the HChaCha20 function for this purpose, however this change makes the Curve25519XChaCha20Poly1305 construction implemented by versions earlier than this commit incompatible.

This was an unfortunate oversight in what is otherwise a non-standard construction with no other known implementations to test against. Perhaps libsodium implements this construction and we could try to ensure compatibility there going forward.

The suggestion for any users of the previous implementation is to migrate all ciphertexts to the new construction, as the original construction was broken. Please open an issue if this actually impacts you and you would like help addressing the problem.

This issue likely deserves a RUSTSEC advisory.

cc @alxiong

Previous versions of this crate did not derive a uniformly random key
when used with the XChaCha20Poly1305 AEAD.
The implementation has been updated to use the HChaCha20 function for
this purpose, however this change makes the Curve25519XChaCha20Poly1305
construction implemented by versions earlier than this commit
incompatible.
This was an unfortunate oversight in what is otherwise a non-standard
construction with no other known implementations to test against.
Perhaps libsodium implements this construction and we could try to
ensure compatibility there going forward.
The suggestion for any users of the previous implementation is to
migrate all ciphertexts to the new construction, as the original
construction was broken. Please open an issue if this actually impacts
you and you would like help addressing the problem.
This issue likely deserves a RUSTSEC advisory.
@tarcieritarcieri added the bug Something isn't working label Apr 30, 2021
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

Merging #295 (e622712) into master (2604d2a) will increase coverage by 0.04%.
The diff coverage is 100.00%.

Impacted file tree graph

@@ Coverage Diff @@## master #295 +/- ##
==========================================
+ Coverage 84.43% 84.47% +0.04% 
==========================================
Files 31 31 Lines 1137 1140 +3 ==========================================
+ Hits 960 963 +3 
Misses 177 177 
Impacted FilesCoverage Δ
crypto_box/tests/lib.rs100.00% <ø> (ø)
crypto_box/src/lib.rs88.63% <100.00%> (+0.83%)⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 2604d2a...e622712. Read the comment docs.

@tarcieri
tarcieri merged commit 2d2e588 into masterApr 30, 2021
@tarcieri
tarcieri deleted the crypto_box/fix-xchacha20poly1305-key-derivation branch April 30, 2021 00:37
@tarcieritarcieri mentioned this pull request Apr 30, 2021
@tarcieri

Copy link
Copy Markdown
MemberAuthor

I was going to file a RUSTSEC advisory for this, but then I realized that this may not in fact be a security-critical issue.

Namely, the XChaCha20 construction performs a similar HChaCha20 derivation to derive the ChaCha20 key. In theory, this should produce a uniformly random ChaCha20 key.

The original NaCl crypto_box and its "Curve25519XSalsa20Poly1305" construction uses HSalsa20 twice however, so it is probably best to move forward with this construction as being closer to the XSalsa20-based equivalent, and perhaps there is a reason for the double-HSalsa20 cascade used in the original construction I'm not aware of.

FWIW, I have confirmed that we in theory implement the same construction as libsodium in crypto_box v0.6.0:

https://github.com/jedisct1/libsodium/blob/e1fa9cc/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305.c#L45-L51

I opened #303 to track adding test vectors to ensure that our implementation is compatible with libsodium's.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@codecov-commenter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY] - #295

Merged
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation
Apr 30, 2021
Merged

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY]#295
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation

Conversation

@tarcieri

@tarcieritarcieri commented Apr 30, 2021

Copy link
Copy Markdown
Member

Previous versions of this crate did not derive a uniformly random key when used with the XChaCha20Poly1305 AEAD.

The implementation has been updated to use the HChaCha20 function for this purpose, however this change makes the Curve25519XChaCha20Poly1305 construction implemented by versions earlier than this commit incompatible.

This was an unfortunate oversight in what is otherwise a non-standard construction with no other known implementations to test against. Perhaps libsodium implements this construction and we could try to ensure compatibility there going forward.

The suggestion for any users of the previous implementation is to migrate all ciphertexts to the new construction, as the original construction was broken. Please open an issue if this actually impacts you and you would like help addressing the problem.

This issue likely deserves a RUSTSEC advisory.

cc @alxiong

Previous versions of this crate did not derive a uniformly random key
when used with the XChaCha20Poly1305 AEAD.
The implementation has been updated to use the HChaCha20 function for
this purpose, however this change makes the Curve25519XChaCha20Poly1305
construction implemented by versions earlier than this commit
incompatible.
This was an unfortunate oversight in what is otherwise a non-standard
construction with no other known implementations to test against.
Perhaps libsodium implements this construction and we could try to
ensure compatibility there going forward.
The suggestion for any users of the previous implementation is to
migrate all ciphertexts to the new construction, as the original
construction was broken. Please open an issue if this actually impacts
you and you would like help addressing the problem.
This issue likely deserves a RUSTSEC advisory.
@tarcieritarcieri added the bug Something isn't working label Apr 30, 2021
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

Merging #295 (e622712) into master (2604d2a) will increase coverage by 0.04%.
The diff coverage is 100.00%.

Impacted file tree graph

@@ Coverage Diff @@## master #295 +/- ##
==========================================
+ Coverage 84.43% 84.47% +0.04% 
==========================================
Files 31 31 Lines 1137 1140 +3 ==========================================
+ Hits 960 963 +3 
Misses 177 177 
Impacted FilesCoverage Δ
crypto_box/tests/lib.rs100.00% <ø> (ø)
crypto_box/src/lib.rs88.63% <100.00%> (+0.83%)⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 2604d2a...e622712. Read the comment docs.

@tarcieri
tarcieri merged commit 2d2e588 into masterApr 30, 2021
@tarcieri
tarcieri deleted the crypto_box/fix-xchacha20poly1305-key-derivation branch April 30, 2021 00:37
@tarcieritarcieri mentioned this pull request Apr 30, 2021
@tarcieri

Copy link
Copy Markdown
MemberAuthor

I was going to file a RUSTSEC advisory for this, but then I realized that this may not in fact be a security-critical issue.

Namely, the XChaCha20 construction performs a similar HChaCha20 derivation to derive the ChaCha20 key. In theory, this should produce a uniformly random ChaCha20 key.

The original NaCl crypto_box and its "Curve25519XSalsa20Poly1305" construction uses HSalsa20 twice however, so it is probably best to move forward with this construction as being closer to the XSalsa20-based equivalent, and perhaps there is a reason for the double-HSalsa20 cascade used in the original construction I'm not aware of.

FWIW, I have confirmed that we in theory implement the same construction as libsodium in crypto_box v0.6.0:

https://github.com/jedisct1/libsodium/blob/e1fa9cc/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305.c#L45-L51

I opened #303 to track adding test vectors to ensure that our implementation is compatible with libsodium's.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@codecov-commenter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY] - #295

Merged
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation
Apr 30, 2021
Merged

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY]#295
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation

Conversation

@tarcieri

@tarcieritarcieri commented Apr 30, 2021

Copy link
Copy Markdown
Member

Previous versions of this crate did not derive a uniformly random key when used with the XChaCha20Poly1305 AEAD.

The implementation has been updated to use the HChaCha20 function for this purpose, however this change makes the Curve25519XChaCha20Poly1305 construction implemented by versions earlier than this commit incompatible.

This was an unfortunate oversight in what is otherwise a non-standard construction with no other known implementations to test against. Perhaps libsodium implements this construction and we could try to ensure compatibility there going forward.

The suggestion for any users of the previous implementation is to migrate all ciphertexts to the new construction, as the original construction was broken. Please open an issue if this actually impacts you and you would like help addressing the problem.

This issue likely deserves a RUSTSEC advisory.

cc @alxiong

Previous versions of this crate did not derive a uniformly random key
when used with the XChaCha20Poly1305 AEAD.
The implementation has been updated to use the HChaCha20 function for
this purpose, however this change makes the Curve25519XChaCha20Poly1305
construction implemented by versions earlier than this commit
incompatible.
This was an unfortunate oversight in what is otherwise a non-standard
construction with no other known implementations to test against.
Perhaps libsodium implements this construction and we could try to
ensure compatibility there going forward.
The suggestion for any users of the previous implementation is to
migrate all ciphertexts to the new construction, as the original
construction was broken. Please open an issue if this actually impacts
you and you would like help addressing the problem.
This issue likely deserves a RUSTSEC advisory.
@tarcieritarcieri added the bug Something isn't working label Apr 30, 2021
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

Merging #295 (e622712) into master (2604d2a) will increase coverage by 0.04%.
The diff coverage is 100.00%.

Impacted file tree graph

@@ Coverage Diff @@## master #295 +/- ##
==========================================
+ Coverage 84.43% 84.47% +0.04% 
==========================================
Files 31 31 Lines 1137 1140 +3 ==========================================
+ Hits 960 963 +3 
Misses 177 177 
Impacted FilesCoverage Δ
crypto_box/tests/lib.rs100.00% <ø> (ø)
crypto_box/src/lib.rs88.63% <100.00%> (+0.83%)⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 2604d2a...e622712. Read the comment docs.

@tarcieri
tarcieri merged commit 2d2e588 into masterApr 30, 2021
@tarcieri
tarcieri deleted the crypto_box/fix-xchacha20poly1305-key-derivation branch April 30, 2021 00:37
@tarcieritarcieri mentioned this pull request Apr 30, 2021
@tarcieri

Copy link
Copy Markdown
MemberAuthor

I was going to file a RUSTSEC advisory for this, but then I realized that this may not in fact be a security-critical issue.

Namely, the XChaCha20 construction performs a similar HChaCha20 derivation to derive the ChaCha20 key. In theory, this should produce a uniformly random ChaCha20 key.

The original NaCl crypto_box and its "Curve25519XSalsa20Poly1305" construction uses HSalsa20 twice however, so it is probably best to move forward with this construction as being closer to the XSalsa20-based equivalent, and perhaps there is a reason for the double-HSalsa20 cascade used in the original construction I'm not aware of.

FWIW, I have confirmed that we in theory implement the same construction as libsodium in crypto_box v0.6.0:

https://github.com/jedisct1/libsodium/blob/e1fa9cc/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305.c#L45-L51

I opened #303 to track adding test vectors to ensure that our implementation is compatible with libsodium's.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@codecov-commenter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY] - #295

Merged
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation
Apr 30, 2021
Merged

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY]#295
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation

Conversation

@tarcieri

@tarcieritarcieri commented Apr 30, 2021

Copy link
Copy Markdown
Member

Previous versions of this crate did not derive a uniformly random key when used with the XChaCha20Poly1305 AEAD.

The implementation has been updated to use the HChaCha20 function for this purpose, however this change makes the Curve25519XChaCha20Poly1305 construction implemented by versions earlier than this commit incompatible.

This was an unfortunate oversight in what is otherwise a non-standard construction with no other known implementations to test against. Perhaps libsodium implements this construction and we could try to ensure compatibility there going forward.

The suggestion for any users of the previous implementation is to migrate all ciphertexts to the new construction, as the original construction was broken. Please open an issue if this actually impacts you and you would like help addressing the problem.

This issue likely deserves a RUSTSEC advisory.

cc @alxiong

Previous versions of this crate did not derive a uniformly random key
when used with the XChaCha20Poly1305 AEAD.
The implementation has been updated to use the HChaCha20 function for
this purpose, however this change makes the Curve25519XChaCha20Poly1305
construction implemented by versions earlier than this commit
incompatible.
This was an unfortunate oversight in what is otherwise a non-standard
construction with no other known implementations to test against.
Perhaps libsodium implements this construction and we could try to
ensure compatibility there going forward.
The suggestion for any users of the previous implementation is to
migrate all ciphertexts to the new construction, as the original
construction was broken. Please open an issue if this actually impacts
you and you would like help addressing the problem.
This issue likely deserves a RUSTSEC advisory.
@tarcieritarcieri added the bug Something isn't working label Apr 30, 2021
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

Merging #295 (e622712) into master (2604d2a) will increase coverage by 0.04%.
The diff coverage is 100.00%.

Impacted file tree graph

@@ Coverage Diff @@## master #295 +/- ##
==========================================
+ Coverage 84.43% 84.47% +0.04% 
==========================================
Files 31 31 Lines 1137 1140 +3 ==========================================
+ Hits 960 963 +3 
Misses 177 177 
Impacted FilesCoverage Δ
crypto_box/tests/lib.rs100.00% <ø> (ø)
crypto_box/src/lib.rs88.63% <100.00%> (+0.83%)⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 2604d2a...e622712. Read the comment docs.

@tarcieri
tarcieri merged commit 2d2e588 into masterApr 30, 2021
@tarcieri
tarcieri deleted the crypto_box/fix-xchacha20poly1305-key-derivation branch April 30, 2021 00:37
@tarcieritarcieri mentioned this pull request Apr 30, 2021
@tarcieri

Copy link
Copy Markdown
MemberAuthor

I was going to file a RUSTSEC advisory for this, but then I realized that this may not in fact be a security-critical issue.

Namely, the XChaCha20 construction performs a similar HChaCha20 derivation to derive the ChaCha20 key. In theory, this should produce a uniformly random ChaCha20 key.

The original NaCl crypto_box and its "Curve25519XSalsa20Poly1305" construction uses HSalsa20 twice however, so it is probably best to move forward with this construction as being closer to the XSalsa20-based equivalent, and perhaps there is a reason for the double-HSalsa20 cascade used in the original construction I'm not aware of.

FWIW, I have confirmed that we in theory implement the same construction as libsodium in crypto_box v0.6.0:

https://github.com/jedisct1/libsodium/blob/e1fa9cc/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305.c#L45-L51

I opened #303 to track adding test vectors to ensure that our implementation is compatible with libsodium's.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@codecov-commenter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY] - #295

Merged
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation
Apr 30, 2021
Merged

crypto_box: fix XChaCha20Poly1305 key derivation [SECURITY]#295
tarcieri merged 1 commit into
masterfrom
crypto_box/fix-xchacha20poly1305-key-derivation

Conversation

@tarcieri

@tarcieritarcieri commented Apr 30, 2021

Copy link
Copy Markdown
Member

Previous versions of this crate did not derive a uniformly random key when used with the XChaCha20Poly1305 AEAD.

The implementation has been updated to use the HChaCha20 function for this purpose, however this change makes the Curve25519XChaCha20Poly1305 construction implemented by versions earlier than this commit incompatible.

This was an unfortunate oversight in what is otherwise a non-standard construction with no other known implementations to test against. Perhaps libsodium implements this construction and we could try to ensure compatibility there going forward.

The suggestion for any users of the previous implementation is to migrate all ciphertexts to the new construction, as the original construction was broken. Please open an issue if this actually impacts you and you would like help addressing the problem.

This issue likely deserves a RUSTSEC advisory.

cc @alxiong

Previous versions of this crate did not derive a uniformly random key
when used with the XChaCha20Poly1305 AEAD.
The implementation has been updated to use the HChaCha20 function for
this purpose, however this change makes the Curve25519XChaCha20Poly1305
construction implemented by versions earlier than this commit
incompatible.
This was an unfortunate oversight in what is otherwise a non-standard
construction with no other known implementations to test against.
Perhaps libsodium implements this construction and we could try to
ensure compatibility there going forward.
The suggestion for any users of the previous implementation is to
migrate all ciphertexts to the new construction, as the original
construction was broken. Please open an issue if this actually impacts
you and you would like help addressing the problem.
This issue likely deserves a RUSTSEC advisory.
@tarcieritarcieri added the bug Something isn't working label Apr 30, 2021
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

Merging #295 (e622712) into master (2604d2a) will increase coverage by 0.04%.
The diff coverage is 100.00%.

Impacted file tree graph

@@ Coverage Diff @@## master #295 +/- ##
==========================================
+ Coverage 84.43% 84.47% +0.04% 
==========================================
Files 31 31 Lines 1137 1140 +3 ==========================================
+ Hits 960 963 +3 
Misses 177 177 
Impacted FilesCoverage Δ
crypto_box/tests/lib.rs100.00% <ø> (ø)
crypto_box/src/lib.rs88.63% <100.00%> (+0.83%)⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 2604d2a...e622712. Read the comment docs.

@tarcieri
tarcieri merged commit 2d2e588 into masterApr 30, 2021
@tarcieri
tarcieri deleted the crypto_box/fix-xchacha20poly1305-key-derivation branch April 30, 2021 00:37
@tarcieritarcieri mentioned this pull request Apr 30, 2021
@tarcieri

Copy link
Copy Markdown
MemberAuthor

I was going to file a RUSTSEC advisory for this, but then I realized that this may not in fact be a security-critical issue.

Namely, the XChaCha20 construction performs a similar HChaCha20 derivation to derive the ChaCha20 key. In theory, this should produce a uniformly random ChaCha20 key.

The original NaCl crypto_box and its "Curve25519XSalsa20Poly1305" construction uses HSalsa20 twice however, so it is probably best to move forward with this construction as being closer to the XSalsa20-based equivalent, and perhaps there is a reason for the double-HSalsa20 cascade used in the original construction I'm not aware of.

FWIW, I have confirmed that we in theory implement the same construction as libsodium in crypto_box v0.6.0:

https://github.com/jedisct1/libsodium/blob/e1fa9cc/src/libsodium/crypto_box/curve25519xchacha20poly1305/box_curve25519xchacha20poly1305.c#L45-L51

I opened #303 to track adding test vectors to ensure that our implementation is compatible with libsodium's.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@tarcieri@codecov-commenter