mirror of
https://github.com/nspcc-dev/neofs-s3-gw.git
synced 2026-03-01 04:29:15 +00:00
Potentially insecure hkdf use #444
Labels
No labels
I2
I2
I3
I4
S2
S3
S4
S4
U0
U1
U2
U2
U3
U4
U4
auth-mate
blocked
bug
config
dependencies
discussion
documentation
enhancement
epic
feature
go
good first issue
help wanted
performance
question
security
test
tree-service
tree-service
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
nspcc-dev/neofs-s3-gw#444
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @roman-khimov on GitHub (May 14, 2024).
Originally assigned to: @smallhive on GitHub.
Current Behavior
kdf := hkdf.New(hash, secret, nil, nil). No salt, no app-specific info.Expected Behavior
App-specific info and salt used.
Possible Solution
Hardcode info, add some salt. Breaking change, but the gateway is not used in production.
Your Environment
@roman-khimov commented on GitHub (Jun 28, 2024):
Salt is to be stored somewhere nearby, as usual.
@cthulhu-rider commented on GitHub (Jul 3, 2024):
what do u mean - in what storage?