Connection tokens and NIP-46 request ids are generated with Math.random() #56

Open
opened 2026-10-09 17:17:52 +00:00 by padreug · 0 comments
Owner

src/daemon/admin/commands/create_new_token.ts:18 mints the bearer token a client redeems for a KeyUser binding with Math.random() (V8 xorshift128+, state recoverable from a few observed outputs). The same RNG produces the NIP-46 request ids that gate the admin approval callback (src/daemon/nip46/transport.ts:133, src/nip46-client.ts:74) and the fallback usernames in create_account.ts:77 / client.ts:77.

Impact: an attacker who observes a few issued tokens (they appear in get_key_tokens output and transit relays) can predict outstanding ones and redeem them first; predictable request ids also lower the bar for the response-spoofing issue filed separately.

Fix direction: crypto.randomBytes(32).toString('hex') for tokens; crypto.randomBytes(16) (hex or base64url) for request ids; grep for every remaining Math.random in src/ and replace the security-relevant ones.

Found during reforge run #1 (sandbox nsecbunkerd#7).

`src/daemon/admin/commands/create_new_token.ts:18` mints the bearer token a client redeems for a KeyUser binding with `Math.random()` (V8 xorshift128+, state recoverable from a few observed outputs). The same RNG produces the NIP-46 request ids that gate the admin approval callback (`src/daemon/nip46/transport.ts:133`, `src/nip46-client.ts:74`) and the fallback usernames in `create_account.ts:77` / `client.ts:77`. Impact: an attacker who observes a few issued tokens (they appear in `get_key_tokens` output and transit relays) can predict outstanding ones and redeem them first; predictable request ids also lower the bar for the response-spoofing issue filed separately. Fix direction: `crypto.randomBytes(32).toString('hex')` for tokens; `crypto.randomBytes(16)` (hex or base64url) for request ids; grep for every remaining `Math.random` in `src/` and replace the security-relevant ones. Found during reforge run #1 (sandbox nsecbunkerd#7).
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/nsecbunkerd#56
No description provided.