Secret encryption vulnerable to brute-force attacks
Package
Authenticator Extension
(Chrome Web Store)
Affected versions
<=7.0.0
Patched versions
>=8.0.0
Authenticator Extension
(Firefox Add-ons)
<=7.0.0
>=8.0.0
Authenticator Extension
(Edge Add-ons)
<=7.0.0
>=8.0.0
Summary
In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key.
Recommended Actions
References
Acknowledgements
We would like to thank Laurent Weber, CISO of the University of Luxembourg for sharing and sponsoring the code review which discovered this vulnerability.