Comments (7)
NPM release should be available in a moment.
from simple-crypto-js.
@paragonie-scott Thanks for the recommendation. Should have been considered before. I'll try to implements a better algorithm.
from simple-crypto-js.
If you don't have any of the algorithms available to you, you might have to follow in the footsteps of @defuse and implement AES-CTR + HMAC-SHA2 (Encrypt then MAC) as detailed here.
It's less simple internally, but it'll remain simple for your users.
from simple-crypto-js.
👋 Hey! We've recently opened a bug bounty against this issue, so if you want to get rewarded 💰 for fixing this vulnerability 🕷, head over to https://huntr.dev!
from simple-crypto-js.
Hey, guys. I'm facing the following problem: if I add any characters to the end of an encrypted string, the decrypt function will still decrypt correctly. This is a huge problem for me because I'm using the simpleCrypto to generate a unique code and I cannot have two different encrypted strings resulting in the same decrypted object.
from simple-crypto-js.
See #17 for a suggested fix.
from simple-crypto-js.
Sorry for very late reply. Already merged #17.
from simple-crypto-js.
Related Issues (20)
- compatible with react-native? HOT 1
- Warning - crypto-js is currently broken
- Is there an implementation of this lib in PHP? HOT 1
- BUG: SimpleCrypto sees two numbers at the beginning of a string and encrypts it as a number, cutting off the rest of the string. HOT 10
- Empty string encryption HOT 6
- Error: Unable to resolve module `crypto` from `node_modules/simple-crypto-js/node_modules/crypto-js/core.js`: crypto could not be found within the project HOT 3
- Not working anymore in React Native / Expo HOT 4
- Differents behavior on differents env HOT 1
- Getting "Error: Invalid encrypted text received. Decryption halted" while decryption HOT 8
- 0 gets removed when encrypting a number string with leading 0 HOT 2
- Consider adding backward compatiblity HOT 6
- Cannot use namespace 'WordArray' as a type - TypeScript 3 HOT 1
- How to change cipherText length
- Big numbers don't work HOT 1
- How do I determine the IV being used?
- Invalid encrypted text received. Decryption halted HOT 1
- Typescript: Cannot find namespace (lib)
- Typescript: failed to parse source map
- Since crypto-js 4.2 (yesterday) decryption of previously encrypted values fail
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from simple-crypto-js.