Entropy Removed to Silence a Warning — JavaScript Bug Hunt
Modelled on the Debian OpenSSL disaster (CVE-2008-0166): a maintainer removed a line that fed uninitialised memory into the random pool because it tripped a…
- Language: JavaScript
- Layer: Backend
- Difficulty: Medium
- Concepts: Security, Randomness
- Modelled on: Debian OpenSSL · CVE-2008-0166
- Visible tests: different entropy gives different keys; different pids still give different keys
- Reward: 50 XP for a complete fix
Briefing
Modelled on the Debian OpenSSL disaster (CVE-2008-0166): a maintainer removed a line that fed uninitialised memory into the random pool because it tripped a Valgrind warning. With it went almost all the entropy — the only varying input left was the process ID, so the whole distribution could only generate about 32,767 distinct keys.
keygen.js has the same shape: it accepts a seed of real entropy but never mixes it in.
Fix generateKey so the supplied entropy actually determines the key.
Bug report
BUG-DSA1571 · Priority: Critical · Reported by: security research
generateKey(entropy, pid):
- must produce a key that depends on BOTH arguments
- two different entropy values with the same pid must give different keys
Observed: every machine with pid 4242 generates the identical key regardless of the entropy handed to it. Scanning the keyspace takes seconds.
Logs
[keygen] collision: entropy=91117 and entropy=55051 produced the same key
[keygen] distinct keys observed across 10000 runs: 4The code as shipped
src/crypto/keygen.js (editable)
// Derives a key from the entropy pool and the process id.
exports.generateKey = function (entropy, pid) {
var state = 5381;
// NOTE: mixing the entropy pool tripped a memory checker, so it was removed.
state = (state * 33 + pid) % 2147483647;
state = (state * 33 + 17) % 2147483647;
return state;
};
Read-only context: src/crypto/POLICY.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.