Key-at-rest encryption is an unsalted SHA-256 KDF + unauthenticated AES-256-CBC #55
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
src/config/keys.ts:5derives the AES key ascrypto.createHash('sha256').update(passphrase).digest()— no salt, no work factor — and:7encrypts withaes-256-cbc, no MAC/AEAD. Anyone holdingnsecbunker.json(backup, leaked volume, loose perms) can brute-force the passphrase at raw-hash speed, and a tampered blob decrypts to garbage or attacker-shaped plaintext with no integrity failure. With autounlock (#16) every key on a host sits under one passphrase, so one crack = every key.Impact: custodial-key compromise from a config-file disclosure, which is the highest-value target in the system.
Fix direction: per-key random salt + scrypt (N=2^16, NIP-49 defaults) + AES-256-GCM (or go the whole way to NIP-49
ncryptsec). Keep a read-only legacy path for existing{iv,data}blobs and re-encrypt lazily on next write, or run a one-shot backfill (cheap for us: single autounlock passphrase). Sandbox PR sandbox-team/nsecbunkerd#25 commit 1 is a working implementation with tests (tests/keys.test.ts) that can be ported nearly verbatim; call sites to touch areadd.ts,start.ts,create_new_key.ts,run.ts unlockKey.Found during reforge run #1 (sandbox nsecbunkerd#5).