JavaScript Misdirection Contest #0

See http://misdirect.ion.land

HTML

<!-- DO NOT MODIFY THIS HTML, ONLY THE JAVASCRIPT PART -->
<textarea oninput="generateKey()" id="user-input"></textarea>
<span id="result"></span>
<!-- DO NOT MODIFY THIS HTML, ONLY THE JAVASCRIPT PART -->

CSS

/* DO NOT MODIFY THIS CSS, ONLY THE JAVASCRIPT PART */

JavaScript

/*
  Entry for the JavaScript Misdirection Contest
  http://misdirect.ion.land/

  github:levoroxi - original code GNU GPLv3

  For the love of God, and all that is holy, don't fucking use this!

  To watch the obvious malice occur, run an HTTP server on Port 80
  of your localhost and watch the GET requests come in with the
  generated key.

  Nearly every bug in here is plausibly deniable to someone that
  does not have a good sense of cryptography and protocol design,
  even if they DO know JavaScript somewhat well. Nearly all
  malicious mistakes are plausible typos in the code or design.

  To understand all of the horrible ways this cargo-cult-crypto
  disaster fucks you over in generating something secure, see the
  associated README.md.

  tl;dr: If you actually want security, and not obfuscation, don't
         roll your own crypto, and don't let some other guy that
         isn't a vetted crypto expert do it, either.
*/

function generateKey() {
  // Implement this function
  var input = document.getElementById('user-input').value;
  var k = new Keygen();
  outputToScreen(k.generate(input));
}

// output the keygen info
var outputToScreen = function(str) {
  var output = document.getElementById('result');
  output.innerHTML = '<span style="font-family:monospace; word-wrap:break-word;">' + str + '</span>';
};


// A secure keygen using the SHA1 hash function.
// Creates a secure random hash depending on data the user
// inputs, and uses the HTML5 Web Cryptography Library
// if at all possible for its hash functions and random values
// for extra security outside of the JavaScript userspace.
var Keygen = function() {

  // Special pepper for KDF
  // See https://en.wikipedia.org/wiki/Pepper_%28cryptography%29
  // generated with bcrypt with cost factor 12 for extra security
  // See http://www.usenix.org/events/usenix99/provos.html
  this.pepper = '$2b$12$fuNLEHcWI8PbH7a5WCj/wuYb8h40.jK2lZXLLF7mgSwOmeisBJRzu';

  // Attempt to use the HTML5 Web...