Add salt to password hash and store it in an extra chunk

Add a salt that is appended to the input password and is stored in the `saLt` chunk
develop
trivernis 5 years ago
parent e0c508fb3c
commit a3d43dc9be

@ -25,6 +25,7 @@ func check(err error) {
} }
} }
const saltChunkName = "saLt"
const chunkName = "crPt" const chunkName = "crPt"
const chunkSize = 0x100000 const chunkSize = 0x100000
@ -69,8 +70,10 @@ func EncryptDataPng(f *os.File, fin *os.File, fout *os.File) {
check(err) check(err)
inputData, err := ioutil.ReadAll(fin) inputData, err := ioutil.ReadAll(fin)
check(err) check(err)
inputData, err = encryptData(inputData) inputData, salt := encryptData(inputData)
check(err) check(err)
saltChunk := CreateChunk(salt, saltChunkName)
png.AddMetaChunk(saltChunk)
chunkCount := int(math.Ceil(float64(len(inputData)) / chunkSize)) chunkCount := int(math.Ceil(float64(len(inputData)) / chunkSize))
for i := 0; i < chunkCount; i++ { for i := 0; i < chunkCount; i++ {
dataStart := i * chunkSize dataStart := i * chunkSize
@ -87,12 +90,17 @@ func DecryptDataPng(f *os.File, fout *os.File) {
png := PngData{} png := PngData{}
err := png.Read(f) err := png.Read(f)
check(err) check(err)
salt := make([]byte, 0)
saltChunk := png.GetChunk(saltChunkName)
if saltChunk != nil {
salt = append(salt, saltChunk.data...)
}
var data []byte var data []byte
for _, cryptChunk := range png.GetChunksByName(chunkName) { for _, cryptChunk := range png.GetChunksByName(chunkName) {
data = append(data, cryptChunk.data...) data = append(data, cryptChunk.data...)
} }
if len(data) > 0 { if len(data) > 0 {
data, err = decryptData(data) data, err = decryptData(data, salt)
if err != nil { if err != nil {
log.Println("\nThe provided password is probably incorrect.") log.Println("\nThe provided password is probably incorrect.")
} }
@ -105,26 +113,36 @@ func DecryptDataPng(f *os.File, fout *os.File) {
} }
// creates an encrypted png chunk // creates an encrypted png chunk
func encryptData(data []byte) ([]byte, error) { func encryptData(data []byte) ([]byte, []byte) {
key := readPassword() key, salt := readPassword(nil)
return encrypt(key, data) encData, err := encrypt(key, data)
check(err)
return encData, salt
} }
// decrypts the data of a png chunk // decrypts the data of a png chunk
func decryptData(data []byte) ([]byte, error) { func decryptData(data []byte, salt []byte) ([]byte, error) {
key := readPassword() key, _ := readPassword(&salt)
return decrypt(key, data) return decrypt(key, data)
} }
// reads a password from the terminal // reads a password from the terminal
// turns off the input for the typing of the password // turns off the input for the typing of the password
func readPassword() []byte { func readPassword(passwordSalt *[]byte) ([]byte, []byte) {
fmt.Print("Password: ") fmt.Print("Password: ")
bytePw, err := terminal.ReadPassword(int(syscall.Stdin)) bytePw, err := terminal.ReadPassword(int(syscall.Stdin))
check(err) check(err)
hash := sha512.New512_256() hash := sha512.New512_256()
hash.Write(bytePw) if passwordSalt != nil {
return hash.Sum(nil) hash.Write(append(*passwordSalt, bytePw...))
return hash.Sum(nil), *passwordSalt
} else {
salt := make([]byte, 32)
_, err = io.ReadFull(rand.Reader, salt)
check(err)
hash.Write(append(salt, bytePw...))
return hash.Sum(nil), salt
}
} }
// encrypt and decrypt functions taken from // encrypt and decrypt functions taken from

Loading…
Cancel
Save