Key material from kotlin.random.Random: 4S master key and default pickle key need a CSPRNG (§9) #121
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
SessionCrypto.setupSecretStorage() creates the 4S master key with kotlin.random.Random.nextBytes(32) — a non-cryptographic PRNG on every platform — and KatrixSession uses the same for the ephemeral default pickle key (D14). The recovery key sealing cross-signing seeds + backup key must be unpredictable (§9). Fix: a SecureRandom expect/actual seam in katrix-crypto (mirroring transport's OidcCrypto actuals: JVM/Android SecureRandom, Apple arc4random_buf, js/wasm crypto.getRandomValues, linux getrandom), used by 4S setup, the pickle-key default, and the #106 QR shared secret (which is why this lands now, discovered scoping #106).