generate the websocket handshake nonce with a secure prng - #63865
Open
ubeddulla wants to merge 1 commit into
Open
generate the websocket handshake nonce with a secure prng#63865ubeddulla wants to merge 1 commit into
ubeddulla wants to merge 1 commit into
Conversation
|
Thank you for your contribution! This project uses Gerrit for code reviews. Your pull request has automatically been converted into a code review at: https://dart-review.googlesource.com/c/sdk/+/526540 Please wait for a developer to review your code review at the above link; you can speed up the review if you sign into Gerrit and manually add a reviewer that has recently worked on the relevant code. See CONTRIBUTING.md to learn how to upload changes to Gerrit directly. Additional commits pushed to this PR will update both the PR and the corresponding Gerrit CL. After the review is complete on the CL, your reviewer will merge the CL (automatically closing this PR). |
|
Gerrit CL has been approved, please wait for a reviewer to merge it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
_WebSocketImpl.connect builds the 16-byte Sec-WebSocket-Key nonce from
dart:math'sRandom(), whose default seed is only 32 bits wide (_Random._nextSeedreturnsstate & 0xFFFFFFFF), so the 128-bit handshake key really carries at most 32 bits of entropy and the generator state behind an observed key can be recovered by exhaustive search over the seed space in about seven seconds on one core. RFC 6455 asks for an unpredictable nonce because that is what stops an attacker who can talk to the same origin from precomputing a matching Sec-WebSocket-Accept and persuading an intermediary that a non-WebSocket response completed the handshake. This switches to_CryptoUtils.getRandomBytes, which isRandom.secure()backed and is already what the same file uses for frame masking keys.Contribution guidelines:
dart format.Note that this repository uses Gerrit for code reviews. Your pull request will be automatically converted into a Gerrit CL and a link to the CL written into this PR. The review will happen on Gerrit but you can also push additional commits to this PR to update the code review.