T09 · Insecure Skill Coding Practices
- Location
authlock_cli.py:107- Finding
Plaintext TOTP Seed Allows Offline Vault Decryption
- Content
View full analysis
bytes: """Derive encryption key from TOTP seed""" password = seed.encode() if pin: password = (seed + pin).encode() ``` The initialization logic stores that seed directly: ```python config["totp_seed"] = seed config["created_at"] = datetime.utcnow().isoformat() + "Z" config["level"] = level_name save_config(home, config) ``` ### Technical Analysis The TOTP seed serves two security roles: 1. It is the shared secret used to generate and verify TOTP codes. 2. It is the password material from which vault encryption keys are derived. The seed is stored as plaintext JSON in `config.json`. Neither `save_config()` nor the directory initialization code explicitly enforces restrictive permissions on this file. Consequently, its effective permissions depend on the process umask and pre-existing filesystem state. Possession of the seed is sufficient to reproduce the PBKDF2-derived key for every sealed record. An attacker does not need to invoke `cmd_open()`, satisfy its TOTP check, or wait for a valid TOTP interval. The TOTP verification is only an application-level authorization check and is not cryptographically required for decryption. This undermines the declared “MFA-bound” property. It also creates a single point of compromise because the same long-lived seed protects all records in the selected AuthLock location. ### Attack Path 1. An attacker gains read access to `.authlock/config.json`, such as through permissive file permissions, a wo ...[truncated 1168 chars]- Remediation
View remediation
