Entropy Removed to Silence a Warning — JavaScript Bug Hunt

Modelled on the Debian OpenSSL disaster (CVE-2008-0166): a maintainer removed a line that fed uninitialised memory into the random pool because it tripped a…

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Medium
  • Concepts: Security, Randomness
  • Modelled on: Debian OpenSSL · CVE-2008-0166
  • Visible tests: different entropy gives different keys; different pids still give different keys
  • Reward: 50 XP for a complete fix

Briefing

Modelled on the Debian OpenSSL disaster (CVE-2008-0166): a maintainer removed a line that fed uninitialised memory into the random pool because it tripped a Valgrind warning. With it went almost all the entropy — the only varying input left was the process ID, so the whole distribution could only generate about 32,767 distinct keys.

keygen.js has the same shape: it accepts a seed of real entropy but never mixes it in.

Fix generateKey so the supplied entropy actually determines the key.

Bug report

BUG-DSA1571 · Priority: Critical · Reported by: security research

generateKey(entropy, pid):

  • must produce a key that depends on BOTH arguments
  • two different entropy values with the same pid must give different keys

Observed: every machine with pid 4242 generates the identical key regardless of the entropy handed to it. Scanning the keyspace takes seconds.

Logs

[keygen] collision: entropy=91117 and entropy=55051 produced the same key
[keygen] distinct keys observed across 10000 runs: 4

The code as shipped

src/crypto/keygen.js (editable)

// Derives a key from the entropy pool and the process id.
exports.generateKey = function (entropy, pid) {
  var state = 5381;
  // NOTE: mixing the entropy pool tripped a memory checker, so it was removed.
  state = (state * 33 + pid) % 2147483647;
  state = (state * 33 + 17) % 2147483647;
  return state;
};

Read-only context: src/crypto/POLICY.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.