Skip to content

fix hybrid key ex blunder - #17

Merged
sz3 merged 4 commits into
masterfrom
v4.5
Jan 9, 2026
Merged

sz3 merged 4 commits into
masterfrom
v4.5

Conversation

@sz3

@sz3 sz3 commented Jan 9, 2026 •

Copy link
Copy Markdown
Owner

This is why they say "don't write cryptography" I suppose (though in this case it's more like "you need someone to remind you to replace the stubbed out xor impl with a real one" 🙃 )

Only effects the hybrid mcleece_crypto_box_seal() and unseal, and is only a theoretical vulnerability afaik. But obviously: it's bad, anyone who used the old version should switch, etc etc. You probably know the drill if you're using experimental cryptography projects like this. 🙂

(as an aside, I'm strongly considering archiving this project. https://github.com/open-quantum-safe/liboqs and other post-quantum crypto libraries have come a long way since mid-2020, and the general lack of PQ crypto libraries back then was the primary motivation for me in throwing this together.)

sz3 added 4 commits October 20, 2025 19:39
I don't know for *sure* this is a cryptography disaster, but I remember
stubbing it out this way, and remember having some misgivings, and
remember wondering if this sort of thing is a failure mode of being a
solo dev on a project.

Anyway, this will break compatibility with v4, but is *clearly* an
improvement imo (and not even that much code 🙃 )
Comment thread src/lib/mcleece/cbox.h
out[i] ^= in[i];
// out = hmac(out + in)
// hmac key is our nonce
crypto_generichash_state hashState;

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Such a small change, too 🫠

@sz3
sz3 merged commit 2c29665 into master Jan 9, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant