[1] https://github.com/FedericoCeratto/owefs/blob/master/pycrypt...
[1] https://github.com/FedericoCeratto/owefs/blob/master/pycrypt...
I have no intention to mislead any user into running it so I'll remove the repository for the time being.
That doesn't immediately mean that the library is useless.
> until that is fixed
I disagree with the word "fixed", as if it's broken. He probably used the highest-level primitives he could to achieve the requirements.
> I've already spotted a few vulnerabilities.
It'd probably be more constructive to open an issue detailing the vulnerabilities rather than saying "I've spotted some, use NaCl" and leaving it at that. What makes you so sure that NaCl is even a suitable replacement without knowing all the considerations that went into the project?
Authenticated encryption? GCM? XTS? Salt the CFB? Guard against interblock attacks?
The crypto needs to be completely reworked. This is an asymmetric kek around symmetric encryption, which is done in many other projects.
Half-backed crypto such as this is worse than no crypto at all, as it lulls people into believing they are using a valid cryptographic system. But, the project implements (poorly) a subset of what is needed and pushes the rest into application code - but app writers don't know this and wouldn't know what to implement even if they know of the shortcomings.
Cryptographers see this all the time. People think they invented a new concept but only implemented a well-known design but did it incompletely and with well-known flaws in the crypto. Then, people defend the system, when it would be far easier to use better primitives.
I doubt eight bytes is enough for cryptography...
If you need random bytes in Python, use os.urandom:
secret = os.urandom(32)
https://docs.python.org/2/library/os.html#os.urandomPretty sad if it is not the case! Interestingly enough, RNG in pycryptodome which I was using for zerodb is urandom. https://github.com/Legrandin/pycryptodome/blob/master/lib/Cr...
Would be interesting to see similar gotchas about that library (though everybody uses PyCrypto, that makes me feel a little paranoid!)
You could make similar threat-model arguments as are made about FDE, but that's not really a good excuse when authentication would be technically easy in this case.