Live data from Hacker News

Show HN: Encrypted Communication via GitHub Using Node.js and SSH Keys

github.com

1–10 of 47 posts

Re: Show HN: Encrypted Communication via GitHub Using Node.js and SSH Keys

#4
post #2

Is this what I think it is? An ECB-mode RSA implementation?

It doesn't appear to be a new implementation. It looks like it uses Node's crypto lib:

https://nodejs.org/api/crypto.html#crypto_crypto_publicencry...

Not sure why it says DSA is supported, the crypto library only supports RSA.

It uses this library that stitches together a PEM from an ssh public key:

https://github.com/dominictarr/ssh-key-to-pem/blob/master/in...

Re: Show HN: Encrypted Communication via GitHub Using Node.js and SSH Keys

#6
post #4
post #2

Is this what I think it is? An ECB-mode RSA implementation?

It doesn't appear to be a new implementation. It looks like it uses Node's crypto lib: https://nodejs.org/api/crypto.html#crypto_crypto_publicencry... Not sure why it says DSA is supported, the crypto library only supports RSA. It uses this library that stitches together a PEM from an ssh public key: https://github.com/dominictarr/ssh-key-to-pem/blob/master/in...

It appears to be using Node's crypto library to apply the RSA transform directly to the plaintext in modulus-size chunks. The problem isn't the quality of the RSA implementation.

Re: Show HN: Encrypted Communication via GitHub Using Node.js and SSH Keys

#7
post #2

Is this what I think it is? An ECB-mode RSA implementation?

    function encrypt(public_key, file) {
     var pem_pub_key = sshKeyToPEM(public_key); // convert rsa to pem
    
     var chunks = [];
     var buffer = new Buffer(fs.readFileSync(file, 'utf8'));
    
     // work around for 214 character limit for encrypting
     // text with small openssh rsa pub key
     for (var i = 0; i 
According to the docs, crypto.publicEncrypt uses OAEP by default, so the bulk of the terribleness should mainly be how horribly slow this is. It does clearly indicate that the author has no idea what they're doing, though.

Edit: For some reason I thought OAEP included randomness. It does not, which should mean you can guess-and-check the plaintext.

Re: Show HN: Encrypted Communication via GitHub Using Node.js and SSH Keys

#8
post #4
post #2

Is this what I think it is? An ECB-mode RSA implementation?

It doesn't appear to be a new implementation. It looks like it uses Node's crypto lib: https://nodejs.org/api/crypto.html#crypto_crypto_publicencry... Not sure why it says DSA is supported, the crypto library only supports RSA. It uses this library that stitches together a PEM from an ssh public key: https://github.com/dominictarr/ssh-key-to-pem/blob/master/in...

The point is that it's using ECB mode with RSA, which indicates the developer has no real knowledge of crypto and is just blindly using pairs of "encrypt/decrypt" functions from Node's built-in crypto lib (which is essentially a thing wrapper around OpenSSL and thus joins its illustrious legacy of encouraging developers to make catastrophic cryptographic implementation mistakes).

In encryptMessage.js, the plaintext is split into chunks, and then chunks.forEach encrypts each chunk (via crypto.publicEncrypt) independently, and concatenates the chunks to form the ciphertext, aka ECB mode. You shouldn't use ECB mode with any cipher because it is not semantically secure. This is Crypto 101.

In addition, it's a bit wacky to use RSA encryption on your entire message because RSA operations are slow and you are limited to encrypting messages that are the length of your RSA key (well, minus the padding, which is how this developer arrived at the "split plaintext into 214 byte chunks" workaround).

A better solution (in every way) would be to use a "hybrid" encryption scheme, similar to TLS or GPG. To do this, you would:

1. Generate a random key for use with a symmetric cipher (e.g. AES-256) 2. Encrypt the plaintext with the random key, using a secure block mode (e.g. CBC, CTR) 3. Encrypt the random key with the RSA public key 4. Package those things together and share it on Github

Efficient and secure. Also totally unnecessary (you basically just reinvented a subset of GPG) but that's neither here nor there.

Re: Show HN: Encrypted Communication via GitHub Using Node.js and SSH Keys

#9
post #7
post #2

Is this what I think it is? An ECB-mode RSA implementation?

function encrypt(public_key, file) { var pem_pub_key = sshKeyToPEM(public_key); // convert rsa to pem var chunks = []; var buffer = new Buffer(fs.readFileSync(file, 'utf8')); // work around for 214 character limit for encrypting // text with small openssh rsa pub key for (var i = 0; i According to the docs, crypto.publicEncrypt uses OAEP by default, so the bulk of the terribleness should mainly be how horribly slow t…

OAEP doesn't allow you to encrypt variable-length data. They may very well be using OAEP, but that's not my point.
Post reply on HN