JavaScript Misdirection Contest #0
See http://misdirect.ion.land
HTML
<!-- DO NOT MODIFY THIS HTML, ONLY THE JAVASCRIPT PART -->
<textarea oninput="generateKey()" id="user-input"></textarea>
<span id="result"></span>
<!-- DO NOT MODIFY THIS HTML, ONLY THE JAVASCRIPT PART -->
CSS
/* DO NOT MODIFY THIS CSS, ONLY THE JAVASCRIPT PART */
JavaScript
/*
Entry for the JavaScript Misdirection Contest
http://misdirect.ion.land/
github:levoroxi - original code GNU GPLv3
For the love of God, and all that is holy, don't fucking use this!
To watch the obvious malice occur, run an HTTP server on Port 80
of your localhost and watch the GET requests come in with the
generated key.
Nearly every bug in here is plausibly deniable to someone that
does not have a good sense of cryptography and protocol design,
even if they DO know JavaScript somewhat well. Nearly all
malicious mistakes are plausible typos in the code or design.
To understand all of the horrible ways this cargo-cult-crypto
disaster fucks you over in generating something secure, see the
associated README.md.
tl;dr: If you actually want security, and not obfuscation, don't
roll your own crypto, and don't let some other guy that
isn't a vetted crypto expert do it, either.
*/
function generateKey() {
// Implement this function
var input = document.getElementById('user-input').value;
var k = new Keygen();
outputToScreen(k.generate(input));
}
// output the keygen info
var outputToScreen = function(str) {
var output = document.getElementById('result');
output.innerHTML = '<span style="font-family:monospace; word-wrap:break-word;">' + str + '</span>';
};
// A secure keygen using the SHA1 hash function.
// Creates a secure random hash depending on data the user
// inputs, and uses the HTML5 Web Cryptography Library
// if at all possible for its hash functions and random values
// for extra security outside of the JavaScript userspace.
var Keygen = function() {
// Special pepper for KDF
// See https://en.wikipedia.org/wiki/Pepper_%28cryptography%29
// generated with bcrypt with cost factor 12 for extra security
// See http://www.usenix.org/events/usenix99/provos.html
this.pepper = '$2b$12$fuNLEHcWI8PbH7a5WCj/wuYb8h40.jK2lZXLLF7mgSwOmeisBJRzu';
// Attempt to use the HTML5 Web...