Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

rebis-dev: "[]" is not handled correctly #1215

Closed
triska opened this issue Jan 14, 2022 · 4 comments
Closed

rebis-dev: "[]" is not handled correctly #1215

triska opened this issue Jan 14, 2022 · 4 comments

Comments

@triska
Copy link
Contributor

triska commented Jan 14, 2022

Reviewing what I wrote in #1193 (comment), I noticed that rebis-dev in fact still contains a mistake in its handling of the aad/1 option!

Specifically, we currently get on rebis-dev, for the query:

?- Key = [0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],
   Nonce = [0,0,0,0,0,0,0,0,0,0,0,0],
   crypto_data_encrypt("", 'chacha20-poly1305', Key, Nonce, _, [tag(Tag),aad("")]).

The result: Tag = [78,185,114,201,168,251,58,27,56,43,180,211,111,95,250,209], which is correct.

However, if we specify for the aad/1 option the string "[]", i.e., if we post:

?- Key = [0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],
   Nonce = [0,0,0,0,0,0,0,0,0,0,0,0],
   crypto_data_encrypt("", 'chacha20-poly1305', Key, Nonce, _, [tag(Tag),aad("[]")]).

Then we get the same Tag as before, i.e., Tag = [78,185,114,201,168,251,58,27,56,43,180,211,111,95,250,209], which is incorrect! The correct result is: [129,92,253,207,2,86,106,239,60,201,211,254,151,176,184,80], which is what master yields.

It is as if the string "[]" is not taken into account at all to compute the authenticator in the rebis-dev branch. Note that already a small change to the authenticated data is expected to effect a huge change in the tag. For example, if we use the string "[" as additional data:

?- Key = [0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],
   Nonce = [0,0,0,0,0,0,0,0,0,0,0,0],
   crypto_data_encrypt("", 'chacha20-poly1305', Key, Nonce, _, [tag(Tag),aad("[")]).

Then we get: Tag = [160,214,128,75,75,133,105,42,194,18,70,151,67,32,242,183], which is correct, and completely different from the tag we get for "" even though only a single character was added.

@triska
Copy link
Contributor Author

triska commented Jan 14, 2022

I think this is a more general problem with how rebis-dev treats the string "[]", maybe due to an issue in the function value_to_str_like.

For example, I get with rebis-dev:

$ touch "[]"
$ scryer-prolog
?- use_module(library(files)).
   true.
?- file_exists("[]").
false.    % expected: true

master correctly yields true.

@triska triska changed the title rebis-dev: "[]" is not treated correctly in encryption rebis-dev: "[]" is not handled correctly Jan 14, 2022
@triska
Copy link
Contributor Author

triska commented Jan 14, 2022

This may be one of the simplest queries to test the issue:

?- Key = [0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0],
   Nonce = [0,0,0,0,0,0,0,0,0,0,0,0],
   crypto_data_encrypt("[]", 'chacha20-poly1305', Key, Nonce, "", []).

Since this unexpectedly succeeds, we see that the string "[]" is erroneously "encrypted" to "", i.e., the empty list.

@triska
Copy link
Contributor Author

triska commented Jan 16, 2022

An even shorter query to test this:

?- crypto_data_hash("", A, []),
   crypto_data_hash("[]", B, []),
   dif(A, B).

This query is expected to succeed.

I have filed #1222 in an attempt to address this issue.

@triska
Copy link
Contributor Author

triska commented Jan 16, 2022

This is now resolved, thank you a lot!

@triska triska closed this as completed Jan 16, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant