ZeroNet security

Created on 20 Mar 2016  路  7Comments  路  Source: HelloZeroNet/ZeroNet

I wonder if we have the same issue as early Bitcoin-core days where people steal the wallet.dat because of plain text.
Should ZN have an encryption mechanism of the user.json and sites.json?
Here is a pywallet encryption function that could be easily inserted into ZN.
https://github.com/jackjack-jj/pywallet/blob/master/pywallet.py#L447

Most helpful comment

give users a choice, why not? for most paranoid ones, let them use passphrase.

All 7 comments

I don't think it's not a real threat: if you loose your bitcoin wallet, then the attacker will get your money. if you looks your users.json then you can register a new one any time.

@HelloZeroNet It's still a threat, because the attacker will be able to decrypt all your ZeroMails and post under your certs

Sure, but he has access to your hdd then your are fucked any way regardless if its encrypted or not.

I'm just saying there is not much motivation to get your users.json, while there is a huge bounty on your wallet.dat.

Encrypting ZeroNet user secrets seems a sane thing to do, and would protect the secrets from machines being compromised (you would need to crack the secret used for the encryption of the data).

But this comes at a cost: users would then need to enter the passphrase when starting ZeroNet: not sure we want to go that way.

@almet

But this comes at a cost: users would then need to enter the passphrase when starting ZeroNet: not sure we want to go that way.

was wondering why isn't this already that way.. we do enter passphrase to decrypt private key when using gpg.

give users a choice, why not? for most paranoid ones, let them use passphrase.

@almet @5hanth @ratijas Maybe the encrypted users.json feature can be implemented as a plugin, similar to the web ui password plugin.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

imachug picture imachug  路  3Comments

iShift picture iShift  路  3Comments

Forbo picture Forbo  路  3Comments

sermont picture sermont  路  3Comments

wigy-opensource-developer picture wigy-opensource-developer  路  4Comments