Răsfoiți Sursa

make key size and authentication tag size explicit instead of trusting on defaults

El RIDO 10 ani în urmă
părinte
comite
a28aebae7d
1 a modificat fișierele cu 4 adăugiri și 2 ștergeri
  1. 4 2
      js/privatebin.js

+ 4 - 2
js/privatebin.js

@@ -491,11 +491,13 @@ $(function() {
          */
          */
         cipher: function(key, password, message)
         cipher: function(key, password, message)
         {
         {
+            // Galois Counter Mode, keysize 256 bit, authentication tag 128 bit
+            var options = {mode: 'gcm', ks: 256, ts: 128};
             if ((password || '').trim().length === 0)
             if ((password || '').trim().length === 0)
             {
             {
-                return sjcl.encrypt(key, this.compress(message), {mode : 'gcm'});
+                return sjcl.encrypt(key, this.compress(message), options);
             }
             }
-            return sjcl.encrypt(key + sjcl.codec.hex.fromBits(sjcl.hash.sha256.hash(password)), this.compress(message), {mode : 'gcm'});
+            return sjcl.encrypt(key + sjcl.codec.hex.fromBits(sjcl.hash.sha256.hash(password)), this.compress(message), options);
         },
         },
 
 
         /**
         /**