Connection tokens and NIP-46 request ids are generated with Math.random() #56
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
src/daemon/admin/commands/create_new_token.ts:18mints the bearer token a client redeems for a KeyUser binding withMath.random()(V8 xorshift128+, state recoverable from a few observed outputs). The same RNG produces the NIP-46 request ids that gate the admin approval callback (src/daemon/nip46/transport.ts:133,src/nip46-client.ts:74) and the fallback usernames increate_account.ts:77/client.ts:77.Impact: an attacker who observes a few issued tokens (they appear in
get_key_tokensoutput and transit relays) can predict outstanding ones and redeem them first; predictable request ids also lower the bar for the response-spoofing issue filed separately.Fix direction:
crypto.randomBytes(32).toString('hex')for tokens;crypto.randomBytes(16)(hex or base64url) for request ids; grep for every remainingMath.randominsrc/and replace the security-relevant ones.Found during reforge run #1 (sandbox nsecbunkerd#7).