Move actual password derivation to separate class
This commit is contained in:
parent
9e18d0deaf
commit
fe54b6dab0
3 changed files with 96 additions and 44 deletions
|
@ -3,6 +3,7 @@
|
|||
#include <unistd.h>
|
||||
|
||||
#import "ScryptPWGen.h"
|
||||
#import "LegacyPasswordGenerator.h"
|
||||
|
||||
OF_APPLICATION_DELEGATE(ScryptPWGen)
|
||||
|
||||
|
@ -34,10 +35,9 @@ showHelp(OFStream *output, bool verbose)
|
|||
OFOptionsParser *optionsParser =
|
||||
[OFOptionsParser parserWithOptions: options];
|
||||
of_unichar_t option;
|
||||
OFString *site, *prompt;
|
||||
size_t length;
|
||||
char *passphrase;
|
||||
OFSHA256Hash *siteHash;
|
||||
unsigned char *output;
|
||||
OFString *site, *prompt;
|
||||
|
||||
while ((option = [optionsParser nextOption]) != '\0') {
|
||||
switch (option) {
|
||||
|
@ -80,9 +80,9 @@ showHelp(OFStream *output, bool verbose)
|
|||
|
||||
if (lengthStr != nil) {
|
||||
@try {
|
||||
_length = (size_t)[lengthStr decimalValue];
|
||||
length = (size_t)[lengthStr decimalValue];
|
||||
|
||||
if (_length < 3)
|
||||
if (length < 3)
|
||||
@throw [OFInvalidFormatException exception];
|
||||
} @catch (OFInvalidFormatException *e) {
|
||||
[of_stderr writeFormat:
|
||||
|
@ -91,8 +91,7 @@ showHelp(OFStream *output, bool verbose)
|
|||
|
||||
[OFApplication terminateWithStatus: 1];
|
||||
}
|
||||
} else
|
||||
_length = 16;
|
||||
}
|
||||
|
||||
if ([[optionsParser remainingArguments] count] != 1) {
|
||||
showHelp(of_stderr, false);
|
||||
|
@ -100,48 +99,32 @@ showHelp(OFStream *output, bool verbose)
|
|||
[OFApplication terminateWithStatus: 1];
|
||||
}
|
||||
|
||||
site = [[optionsParser remainingArguments] firstObject];
|
||||
siteHash = [OFSHA256Hash cryptoHash];
|
||||
[siteHash updateWithBuffer: [site UTF8String]
|
||||
length: [site UTF8StringLength]];
|
||||
|
||||
prompt = [OFString stringWithFormat: @"Passphrase for site \"%@\": ",
|
||||
site];
|
||||
passphrase = getpass([prompt cStringWithEncoding:
|
||||
[OFSystemInfo native8BitEncoding]]);
|
||||
|
||||
output = [self allocMemoryWithSize: _length + 1];
|
||||
LegacyPasswordGenerator *generator =
|
||||
[LegacyPasswordGenerator generator];
|
||||
generator.length = length;
|
||||
generator.site = [[optionsParser remainingArguments] firstObject];
|
||||
|
||||
of_scrypt(8, 524288, 2, [siteHash digest],
|
||||
[[siteHash class] digestSize], passphrase, strlen(passphrase),
|
||||
output, _length);
|
||||
passphrase = getpass(
|
||||
[prompt cStringWithEncoding: [OFSystemInfo native8BitEncoding]]);
|
||||
@try {
|
||||
generator.passphrase = passphrase;
|
||||
|
||||
of_explicit_memset(passphrase, 0, strlen(passphrase));
|
||||
|
||||
/*
|
||||
* This has a bias, but is what scrypt-genpass does. This should be
|
||||
* compatible to passwords generated by scrypt-genpass for now to allow
|
||||
* an easy migration.
|
||||
*
|
||||
* This will be replaced with something better later on and the current
|
||||
* code only available in legacy mode (which can be enabled using a
|
||||
* flag).
|
||||
*/
|
||||
output[0] = "abcdefghijklmnopqrstuvwxyz"[output[0] % 26];
|
||||
output[1] = "0123456789"[output[1] % 10];
|
||||
output[2] = "ABCDEFGHIJKLMNOPQRSTUVWXYZ"[output[2] % 26];
|
||||
|
||||
for (size_t i = 3; i < _length; i++)
|
||||
output[i] = "abcdefghijklmnopqrstuvwxyz"
|
||||
"ABCDEFGHIJKLMNOPQRSTUVWXYZ"
|
||||
"0123456789"[output[i] % (26 + 26 + 10)];
|
||||
|
||||
output[_length] = '\n';
|
||||
|
||||
[of_stdout writeBuffer: output
|
||||
length: _length + 1];
|
||||
|
||||
of_explicit_memset(output, 0, _length + 1);
|
||||
[generator derivePassword];
|
||||
@try {
|
||||
[of_stdout writeBuffer: generator.output
|
||||
length: generator.length];
|
||||
[of_stdout writeBuffer: "\n"
|
||||
length: 1];
|
||||
} @finally {
|
||||
of_explicit_memset(generator.output, 0,
|
||||
generator.length);
|
||||
}
|
||||
} @finally {
|
||||
of_explicit_memset(passphrase, 0, strlen(passphrase));
|
||||
}
|
||||
|
||||
[OFApplication terminate];
|
||||
}
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue