Text Shredder: Peer-to-peer message-based encryption utility
textshredder.codeplex.com
textshredder.codeplex.com
https://textshredder.codeplex.com/SourceControl/latest
(HN breaks the link directly to the code, but add this fragment to go straight to the AES.cs class: "#Code/Release 1.0/ClientLibrary/CryptoProviders/AES.cs")
This is not secure and should include authentication. As far as I know, .NET does not include authenticated cipher modes by default:
http://msdn.microsoft.com/en-us/library/system.security.cryp...
I recommend using a second HMAC key and computing a HMAC over both the IV and ciphertext. Keyczar does something similar:
Serge Vaudenay talked about this 12 years ago:
http://www.iacr.org/cryptodb/archive/2002/EUROCRYPT/2850/285...
The recent Lucky 13 attack was a form of this type of padding oracle attack:
https://www.imperialviolet.org/2013/02/04/luckythirteen.html
Thanks for the constructive feedback. This is why I posted it here and made it open source so I could get peer review, make the utility better and learn a few things along the way.
[1] http://crypto.stackexchange.com/questions/202/should-we-mac-...
Edit: The download button gives me some .exe file and the source code is Microsoft shit. Not gonna work.
Edit2: It seems to use AES ECB. Definitely secure... not https://en.wikipedia.org/wiki/File:Tux_ecb.jpg
Pseudocode of what it does:
function EncryptBlock(data, password)
encrpytedMessage = aes.Encrypt(data, passwd, salt, pbkdf2RoundsCount);
return encrpytedMessage; // sic
function aes.Encrypt(data, pwd, salt, pwd_rounds)
hash = pbkdf2(pwd, salt, rounds);
IV = hash.getBytes(16);
passwd = hash.getBytes(32);
encrypted = aes(data, passwd, IV);
return encrypted;That's the point. Microsoft doesn't release .NET compilers for any other platform than their own, and since I don't use Windows I'm not going to execute this application. Anyone sending messages to me can install GnuPG, something that is available across platforms.
[1] http://msdn.microsoft.com/en-us/library/system.security.cryp...
I'm not sure, but even if it uses CBC internally, the encryptions might still be broken by comparing the first block of each encrypted message, if messages are encrypted with the same password (which is very likely). I've always heard that the IV may never be static.
UPDATE: Not entirely correct, see https://news.ycombinator.com/item?id=7400183.
I haven't had any ideas on how to make it easier to use for people that use windows / don't use the command line. Maybe some type of GPG implementation in javascript for the browser, looking for any ideas / help
http://msdn.microsoft.com/en-us/library/system.security.cryp...
So, it appears to be using CBC. However, their ciphertext is not authenticated so is still insecure.
salt = "$2a$10$67C.GOM1jShOBOM.f.BIAe" // Version 2a and work factor 10.
password = BASE64-ENCODE(BCRYPT(password1 + password2, salt))
rounds = 45000
salt = CSRNG.GetBytes(32)
key + iv = PBKDF2-HMAC-SHA1(password, salt, rounds).GetBytes(32 + 16)
encrypted = BASE64-ENCODE(salt + AES-256-CBC(GZIP(message), key, iv))
The bcrypt implementation comes from [1].The problem it tries to solve is turning a low-entropy passphrase into a 128 bit AES key. That's the problem that a KDF, like PBKDF2, solves.
If they want to make the system stronger, increase the PBKDF2 iterations; lose the bcrypt step. (They could also use a better KDF, like scrypt, instead of PBKDF2; PBKDF2 is fine, though).
Also, compressing breaks semantic security. Don't compress before encrypting.
Edited; briefly thought parent commenter was the author of the tool.
I think the UI is probably easier for a normal user than GPG or somesuch.
I've some strong concerns about the quality of the cypher construction though, just from looking at the comments here.
From my perspective it could be a trojan horse, even if the author claims otherwise all day long.
Bottom line, its security cannot be verified, so this might as well be considered dead in the water as far as being a viable tool for security.
Furthermore even if it was real, using it would limit your communication to people who are running Windows...
Simple fix for all this: release it as an open source project.