Skip to content

doc: warn about GCM authenticity - #18376

Closed
tniessen wants to merge 1 commit into
nodejs:masterfrom
tniessen:doc-add-gcm-auth-tag-length-warning
Closed

doc: warn about GCM authenticity#18376
tniessen wants to merge 1 commit into
nodejs:masterfrom
tniessen:doc-add-gcm-auth-tag-length-warning

Conversation

@tniessen

Copy link
Copy Markdown
Member

Until #17825 lands (which won't be before node 10 is released), the GCM implementation permits short (even single-byte) authentication tag lengths and represents a possible attack vector, compromising the authenticity of data. It is up to the user to validate the length, and this should be noted in the documentation.

#17825 will reduce the chance of improperly passing authentication to 0.00000002% even if the user does not validate the tag length.

Checklist
Affected core subsystem(s)

doc

@nodejs-github-botnodejs-github-bot added crypto Issues and PRs related to the crypto subsystem. doc Issues and PRs related to the documentations. labels Jan 25, 2018
@ChALkeRChALkeR added the security Issues and PRs related to security. label Jan 27, 2018
@tniessen

Copy link
Copy Markdown
MemberAuthor

@tniessen

Copy link
Copy Markdown
MemberAuthor

Landed in a178123.

tniessen added a commit that referenced this pull request Jan 30, 2018
PR-URL: #18376
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
MylesBorins pushed a commit that referenced this pull request Feb 20, 2018
PR-URL: #18376
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
MylesBorins pushed a commit that referenced this pull request Feb 21, 2018
PR-URL: #18376
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
MylesBorins pushed a commit that referenced this pull request Feb 21, 2018
PR-URL: #18376
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
@MylesBorinsMylesBorins mentioned this pull request Feb 21, 2018
MylesBorins pushed a commit that referenced this pull request Mar 20, 2018
PR-URL: #18376
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
MylesBorins pushed a commit that referenced this pull request Mar 28, 2018
PR-URL: #18376
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
MylesBorins pushed a commit that referenced this pull request Mar 30, 2018
PR-URL: #18376
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
@MylesBorinsMylesBorins mentioned this pull request May 2, 2018
MayaLekova pushed a commit to MayaLekova/node that referenced this pull request May 8, 2018
PR-URL: nodejs#18376
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cryptoIssues and PRs related to the crypto subsystem.docIssues and PRs related to the documentations.securityIssues and PRs related to security.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@tniessen@bnoordhuis@jasnell@lpinca@ChALkeR@MylesBorins@nodejs-github-bot