T09 · Insecure Skill Coding Practices
- Location
knowledge_lock.py:321- Finding
Weak Password-Based Key Derivation Enables Efficient Offline Password Guessing
- Content
View full analysis
Vulnerability Details
File Location:
knowledge_lock.py:321-324
Vulnerability Type: Weak cryptographic key derivation
Risk Level: HighVulnerable Code
python def derive_key(password: str) -> bytes: """Derive a Fernet-compatible 32-byte key from a user password.""" digest = hashlib.sha256(password.encode('utf-8')).digest() return base64.urlsafe_b64encode(digest)Technical Analysis
The encryption key is derived by applying a single, unsalted SHA-256 operation to the supplied password. SHA-256 is intentionally fast and is not suitable as a password-based key derivation function.
A
.lockedfile contains a Fernet token that provides an authentication result for each attempted key. Consequently, possession of the encrypted file allows an attacker to perform offline password guessing without interacting with the application or triggering rate limits.The password policy requiring eight characters, uppercase and lowercase letters, and a digit does not guarantee sufficient entropy. Human-selected passwords that satisfy these requirements may still be recovered using dictionaries and mutation rules.
Attack Path
- The attacker obtains a
.lockedfile through local access, an exposed archive, backup leakage, or file sharing. - The attacker extracts the Fernet ciphertext from the file.
- Candidate passwords are generated from password dictionaries or brute-force rules.
- Each candidate is hashed once with SHA-256 and converted into a Fernet key.
- Fernet authentication identifies the correct password offline.
- The attacker decrypts the protected knowledge content.
Impact Assessment
Successful exploitation discloses the complete encrypted portion of the protected document. No operating-system privilege escalation occurs, but the confidentiality boundary promised by the asset-protection feature is compromised for files protected by guessable passwords.
- The attacker obtains a
- Remediation
View remediation
Remediation Suggestions
- Replace the direct SHA-256 derivation with Argon2id, scrypt, or PBKDF2-HMAC using security-reviewed parameters.
- Generate a cryptographically random salt for every encrypted file.
- Store the salt, KDF algorithm, version, and cost parameters in authenticated metadata.
- Prefer Argon2id with calibrated memory, iteration, and parallelism costs appropriate to supported systems.
- Preserve backward compatibility only through an explicit legacy-decryption path, and re-encrypt legacy files after successful decryption.
- Encourage generated high-entropy passphrases rather than relying only on composition rules.
