Repository navigation
c64-https v0.5.0
For demonstration and educational purposes only. It is not cryptographically secure.
Built from 693727e. Submodule pins:
libs/nistcurvesv0.14.0 (was v0.11.2);libs/x25519v0.16.0, now linked into every image;- ip65
25a9c5a(untagged).
This release covers 75 merged PRs since v0.4.3. If you run v0.4.3 or earlier, replace it: two fixes below change what an attacker can do against the uci-comb image, and one fixes handshakes that failed intermittently on every image.
Assets
| image | for | PRG sha256 |
|---|---|---|
c64-https-ip65-onchip |
stock C64 + RR-Net, no REU, no turbo | 78a10748f42553417f5e8a5bfafab9cbc9e70a10fa2821d99dd2680c09753546 |
c64-https-uci-onchip |
U64E / C64 Ultimate, turbo, no REU | da4d607ec2f43f63c49e5e720b6873e6e886e412ceaf3a0968218a2c621f9df4 |
c64-https-uci-comb |
U64E / C64 Ultimate, turbo + REU (fastest) | e6750100fedfbccf47eae4bef0f8f6e83f7705eee672ce42944cf5de3a5e38fc |
c64-https-uci-m3-demo (new) |
U64E with the M3 (ESP32 TLS) firmware | e4814599c783aeefe03d37b194debc067c18afff3589069a97af8630edb34e24 |
Each image ships as a .prg and as a bootable .d64. The disks also contain MANIFEST.txt, build-info.txt and c64-https-listener.py.
New
- A trust policy on the UCI images (#155, phase 2). Each server key is checked against a build-time leaf SPKI pin first (#255), then a signed trust bundle (#262), then trust-on-first-use. Policy and storage: #268; trust store on disk over the Ultimate's DOS: #258. The released UCI images are built with
TRUST_STORE=1, and a release build refuses the test bundle key (#269). This is key pinning, not certificate chain validation. The ip65 image has neither. - Type the host and path at the
Gprompt on the UCI images (#261), instead of rebuilding for each target. - uci-m3, a secondary variant (#271, #276) that hands TLS to the Ultimate's ESP32 (M3 firmware), plus a "just run it" demo disk (#275). It needs firmware implementing M3-SPEC v1 with errata v1.1/v1.2, validated on esp-tls/m3-master
3a1ff9ff(fw 3.15, FPGA 126, ESP 1.309). The in-C64 6510 TLS images above remain the main product. Qexits cleanly (#285). It erases the session's secrets from memory and returns to a working BASIC.- Space for the above. Code nothing can reach is no longer linked (#260), and
uci-combkeeps the code used only outside a connection in the REU, running it from there (#266).
Security-relevant fixes
uci-comb: ECDSA forgery via a collapsed comb table (#216, which bumps nistcurves to v0.14.0 for upstream c64-nist-curves#148). Before v0.13.0 the Lim-Lee comb accepted a signature whose u1·G collapsed to the point at infinity. The table lives in REU bank 2, so whoever can write that bank could get a forged signature accepted. The same bump brings the SPEC §8.2 REU DMA settle fix. The two onchip images do not use the REU for crypto and were not exposed.- An AEAD tag failure now aborts the connection (#240). Previously the client treated it as "incomplete" and kept polling.
- The DRBG has its own key (#279). HKDF and Finished no longer reuse or leak the HMAC-DRBG's key.
- Every REU transfer waits for the bit-6 confirm and a settle (#250, SPEC §8.2).
Correctness
- X25519 intermittently computed a wrong key share (#244), so some handshakes failed with an AEAD error on EncryptedExtensions. This affected all three images, from the first handshake commit onward. Every image now links the
libs/x25519sibling, and the in-tree X25519 is retired (#251). - A second handshake in the same boot failed (#270). The AEAD sequence counters are now reset for each connection.
- Bodies:
- A truncated body is no longer reported as success (#219).
- The UCI truncations behind #211 are fixed: the client now waits for a reply to be valid, not just for BUSY to clear (#238), and every timeout aborts and resets (#241).
- An unframed body counts as complete only on
close_notify(#277). - Chunk sizes are 24-bit (#252).
- The REU body sink is bounded to its region (#273).
- UCI:
Build, test and rigs
- Rebuild tracking:
tools/measure_margins.pymeasures region margins (#248).- Tests:
- Hardware rigs:
- The first HTTPS run over real RR-Net silicon (#200, #205).
Validated
Built from 693727e. make package-verify passed 11/11, and the M3 demo package rebuilds to the same bytes.
Hardware runs:
- Device: U64E, fw 3.15 (git
3a1ff9ff), FPGA 126, core 1.50, 48 MHz. - Target:
https://en.wikipedia.org/wiki/Commodore_64, typed at theGprompt. - Each run used the exact bytes of the released PRG.
| image | result |
|---|---|
uci-onchip |
HTTP 200, 751,848 B == Content-Length |
uci-comb |
HTTP 200, 751,848 B == Content-Length |
uci-m3-demo |
HTTP 200, 751,848 B complete, with the REU disabled; a name mismatch was correctly refused |
ip65-onchip |
boots to the RR-Net banner in VICE (package-verify); no hardware run for this release |
Suites: run_all_tests.py (uci) 434/434, test_trust_release_guard 24/24, check_m3_client 50/50.
What this release does NOT do
- No certificate chain validation on the three 6510 images. The UCI images pin keys (build pin, signed bundle, or trust-on-first-use). The ip65 image accepts any certificate whose signature verifies. (On the M3 demo the ESP32 verifies certificates against its own Mozilla CA store.)
- Server name validation is UCI-only.
- Entropy is weak. The boot seed comes from SID voice 3 and CIA1 timer A. Both run off the system clock, so the seed has far less entropy than its 32 bytes suggest. That is one reason for the disclaimer at the top.
ip65-onchipwas checked only by a VICE boot for this release. Its last run on real RR-Net hardware predates these changes (#200).