From 56d47b757da04bdb4414e350e6438a93242f53c8 Mon Sep 17 00:00:00 2001 From: Jesse Luehrs Date: Wed, 8 Apr 2020 03:45:45 -0400 Subject: mlock sensitive memory --- src/identity.rs | 45 +++++++++++++++++++++++++++------------------ 1 file changed, 27 insertions(+), 18 deletions(-) (limited to 'src/identity.rs') diff --git a/src/identity.rs b/src/identity.rs index 69294ca..1baac0f 100644 --- a/src/identity.rs +++ b/src/identity.rs @@ -2,43 +2,52 @@ use crate::prelude::*; pub struct Identity { pub email: String, - pub enc_key: Vec, - pub mac_key: Vec, - pub master_password_hash: Vec, + pub keys: crate::locked::Keys, + pub master_password_hash: crate::locked::PasswordHash, } impl Identity { - pub fn new(email: &str, password: &str, iterations: u32) -> Result { - let mut key = vec![0_u8; 32]; + pub fn new( + email: &str, + password: &crate::locked::Password, + iterations: u32, + ) -> Result { + let mut keys = crate::locked::Vec::new(); + keys.extend(std::iter::repeat(0).take(64)); + + let enc_key = &mut keys.data_mut()[0..32]; pbkdf2::pbkdf2::>( - password.as_bytes(), + password.password(), email.as_bytes(), iterations as usize, - &mut key, + enc_key, ); - let mut hash = vec![0_u8; 32]; + let mut hash = crate::locked::Vec::new(); + hash.extend(std::iter::repeat(0).take(32)); pbkdf2::pbkdf2::>( - &key, - password.as_bytes(), + enc_key, + password.password(), 1, - &mut hash, + hash.data_mut(), ); - let hkdf = hkdf::Hkdf::::from_prk(&key) + let hkdf = hkdf::Hkdf::::from_prk(enc_key) .map_err(|_| Error::HkdfFromPrk)?; - hkdf.expand(b"enc", &mut key) + hkdf.expand(b"enc", enc_key) .map_err(|_| Error::HkdfExpand)?; - let mut mac_key = vec![0_u8; 32]; - hkdf.expand(b"mac", &mut mac_key) + let mac_key = &mut keys.data_mut()[32..64]; + hkdf.expand(b"mac", mac_key) .map_err(|_| Error::HkdfExpand)?; + let keys = crate::locked::Keys::new(keys); + let master_password_hash = crate::locked::PasswordHash::new(hash); + Ok(Self { email: email.to_string(), - enc_key: key, - mac_key, - master_password_hash: hash, + keys, + master_password_hash, }) } } -- cgit v1.2.3-54-g00ecf