Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

%ELO adaptor reuses a zero IV, breaking AES-GCM security

オープン
#14 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
50/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
停滞
技術スタック
rust

調査の方向性

Read rust/loro-websocket-client/src/lib.rs:1045-1138 and protocol-e2ee.md first. Trace both encode_elo_snapshot_container and the live subscribe_local_update hook, then ensure each encrypted record gets a fresh 12-byte IV while retaining it in the record header for decryption. Done means the zero IV is no longer reused under the same key.

索引モデルが issue の本文から書いたものです。

説明

bug

rust/loro-websocket-client/src/lib.rs:1045-1138

  • The %ELO client sets the IV to [0u8; 12] in both encode_elo_snapshot_container and the live
    subscribe_local_update hook. Every encrypted record therefore repeats the same AES-GCM nonce under the
    same key.
  • protocol-e2ee.md mandates 96-bit unique IVs and warns against reuse; violating that lets an attacker
    recover XORs of plaintexts and eventually the key.
  • Fix: Plug in a CSPRNG (e.g. rand::rngs::OsRng) or a durable per-key counter to emit fresh IVs, and keep
    embedding the 12-byte IV in the record header so receivers can decrypt.
主要言語
TypeScript
スター
40
フォーク
12
平均マージ
4日 1時間
マージ済み PR(30日)
1

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

loro-dev/protocol のほかの issue

loro-dev/protocol の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。