Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
## 2026-02-02 - Constant-time comparison for authentication
**Vulnerability:** Timing attacks in password and token verification.
**Learning:** Using `String.equals()` or `String.equalsIgnoreCase()` for comparing hashes allows an attacker to guess the hash byte-by-byte by measuring the time taken for the comparison.
**Prevention:** Always use `java.security.MessageDigest.isEqual()` for constant-time comparison of sensitive data like hashes or tokens.

## 2026-02-02 - Charset standardization for cryptographic operations
**Vulnerability:** Platform-dependent hashing and encoding.
**Learning:** Using platform default charsets (e.g. `String.getBytes()`) can lead to inconsistent hashes across different environments, potentially locking out users or creating security gaps if different charsets handle certain characters differently.
**Prevention:** Explicitly specify `StandardCharsets.UTF_8` for all cryptographic operations involving string-to-byte or byte-to-string conversions.
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,8 @@
import org.bouncycastle.crypto.digests.SHA256Digest;
import it.richkmeli.jframework.util.TypeConverter;

import java.nio.charset.StandardCharsets;

public class SHA256 {
public static byte[] hash(byte[] input) {
SHA256Digest digest = new SHA256Digest();
Expand All @@ -15,7 +17,7 @@ public static byte[] hash(byte[] input) {

// sha256: string to hex
public static String hash(String input) {
return TypeConverter.bytesToHex(hash(input.getBytes()));
return TypeConverter.bytesToHex(hash(input.getBytes(StandardCharsets.UTF_8)));
}

public static String hashToString(byte[] input) {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,8 @@
import it.richkmeli.jframework.crypto.algorithm.SHA256;
import it.richkmeli.jframework.util.RandomStringGenerator;

import java.nio.charset.Charset;
import java.nio.charset.StandardCharsets;
import java.security.MessageDigest;
import java.util.Base64;

public class PasswordManager {
Expand All @@ -26,20 +27,21 @@ public static String hashPassword(String password, boolean saltEnabled) {

//System.out.println("hashPassword, saltS: " + saltS + " " + saltS.length() + " | hashedPassword: " + hashedPassword + " " + hashedPassword.length());
String out = saltS + hashedPassword;
return Base64.getUrlEncoder().encodeToString(out.getBytes(Charset.defaultCharset()));
return Base64.getUrlEncoder().encodeToString(out.getBytes(StandardCharsets.UTF_8));
}

// hashedPassword = db password, hashedSaltPassword = login password
public static boolean verifyPassword(String hashedPassword, String hashedSaltPassword) {
String decodedHashedPassword = new String(Base64.getUrlDecoder().decode(hashedPassword));
String decodedHashedSaltPassword = new String(Base64.getUrlDecoder().decode(hashedSaltPassword));
String decodedHashedPassword = new String(Base64.getUrlDecoder().decode(hashedPassword), StandardCharsets.UTF_8);
String decodedHashedSaltPassword = new String(Base64.getUrlDecoder().decode(hashedSaltPassword), StandardCharsets.UTF_8);
String salt = decodedHashedSaltPassword.substring(0, 9);
String hashSP = decodedHashedSaltPassword.substring(9);
String hashP = decodedHashedPassword.substring(9);

//System.out.println("verifyPassword, saltS: " + salt + " " + salt.length() + " | hashedSaltPassword: " + hashSP + " " + hashSP.length());
String hp = SHA256.hash(hashP + salt);

return hashSP.equalsIgnoreCase(hp);
// Mitigation of timing attacks using constant-time comparison
return MessageDigest.isEqual(hashSP.getBytes(StandardCharsets.UTF_8), hp.getBytes(StandardCharsets.UTF_8));
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,8 @@ public class RandomStringGenerator {
public static final String ALPHANUMERIC_ALPHABET = "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
public static final String NUMERIC_ALPHABET = "0123456789";

private static final SecureRandom secureRandom = new SecureRandom();

public static String generateAlphanumericString(int length) {
String alphabet = ALPHANUMERIC_ALPHABET;
return generateString(length, alphabet);
Expand All @@ -21,7 +23,6 @@ private static String generateString(int length, String alphabet) {
int alphabetLength = alphabet.length();

StringBuilder result = new StringBuilder();
SecureRandom secureRandom = new SecureRandom();

for (int i = 0; i < length; ++i) {
result.append(alphabet.charAt(secureRandom.nextInt(alphabetLength)));
Expand All @@ -42,11 +43,10 @@ public static String generateBoundedString(int targetStringLength, int leftLimit
//int leftLimit = 97; // letter 'a'
//int rightLimit = 122; // letter 'z'
//int targetStringLength = 10;
SecureRandom random = new SecureRandom();
StringBuilder buffer = new StringBuilder(targetStringLength);
for (int i = 0; i < targetStringLength; i++) {
int randomLimitedInt = leftLimit + (int)
(random.nextFloat() * (rightLimit - leftLimit + 1));
(secureRandom.nextFloat() * (rightLimit - leftLimit + 1));
buffer.append((char) randomLimitedInt);
}
return buffer.toString();
Expand All @@ -55,19 +55,19 @@ public static String generateBoundedString(int targetStringLength, int leftLimit

public static String generateUtf8String(int length) {
byte[] array = new byte[length]; // length is bounded by 7
new SecureRandom().nextBytes(array);
secureRandom.nextBytes(array);
return new String(array, StandardCharsets.UTF_8);
}

public static String generateUtf16String(int length) {
byte[] array = new byte[length]; // length is bounded by 7
new SecureRandom().nextBytes(array);
secureRandom.nextBytes(array);
return new String(array, StandardCharsets.UTF_16);
}

public static String generateASCIItring(int length) {
byte[] array = new byte[length]; // length is bounded by 7
new SecureRandom().nextBytes(array);
secureRandom.nextBytes(array);
return new String(array, StandardCharsets.US_ASCII);
}

Expand Down