Skip to content

generate the websocket handshake nonce with a secure prng - #63865

Open
ubeddulla wants to merge 1 commit into
dart-lang:mainfrom
ubeddulla:websocket-nonce-secure-random
Open

generate the websocket handshake nonce with a secure prng#63865
ubeddulla wants to merge 1 commit into
dart-lang:mainfrom
ubeddulla:websocket-nonce-secure-random

Conversation

@ubeddulla

Copy link
Copy Markdown
Contributor

_WebSocketImpl.connect builds the 16-byte Sec-WebSocket-Key nonce from dart:math's Random(), whose default seed is only 32 bits wide (_Random._nextSeed returns state & 0xFFFFFFFF), so the 128-bit handshake key really carries at most 32 bits of entropy and the generator state behind an observed key can be recovered by exhaustive search over the seed space in about seven seconds on one core. RFC 6455 asks for an unpredictable nonce because that is what stops an attacker who can talk to the same origin from precomputing a matching Sec-WebSocket-Accept and persuading an intermediary that a non-WebSocket response completed the handshake. This switches to _CryptoUtils.getRandomBytes, which is Random.secure() backed and is already what the same file uses for frame masking keys.


  • I've reviewed the contributor guide and applied the relevant portions to this PR.
Contribution guidelines:
  • See our contributor guide for general expectations for PRs.
  • Larger or significant changes should be discussed in an issue before creating a PR.
  • Contributions to our repos should follow the Dart style guide and use dart format.

Note that this repository uses Gerrit for code reviews. Your pull request will be automatically converted into a Gerrit CL and a link to the CL written into this PR. The review will happen on Gerrit but you can also push additional commits to this PR to update the code review.

@copybara-service

Copy link
Copy Markdown

Thank you for your contribution! This project uses Gerrit for code reviews. Your pull request has automatically been converted into a code review at:

https://dart-review.googlesource.com/c/sdk/+/526540

Please wait for a developer to review your code review at the above link; you can speed up the review if you sign into Gerrit and manually add a reviewer that has recently worked on the relevant code. See CONTRIBUTING.md to learn how to upload changes to Gerrit directly.

Additional commits pushed to this PR will update both the PR and the corresponding Gerrit CL. After the review is complete on the CL, your reviewer will merge the CL (automatically closing this PR).

@copybara-service

Copy link
Copy Markdown

Gerrit CL has been approved, please wait for a reviewer to merge it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant