Skip to content

drift v0.1.3

Choose a tag to compare

@aeroxy aeroxy released this 11 Apr 03:54
· 74 commits to master since this release

Security

MITM protection via password authentication and connection fingerprints.

Pure X25519 ECDH is fast and private, but without identity verification any attacker who can intercept the WebSocket connection can complete independent handshakes with both sides. v0.1.3 addresses this with two complementary mechanisms.

Password authentication (--password)

When both sides are started with --password <secret>, the handshake includes a challenge-response step after key exchange:

  1. Server generates a random 32-byte nonce and sends AuthChallenge { nonce }
  2. Client computes HMAC-SHA256(password, nonce || shared_secret) and sends AuthResponse { proof }
  3. Server verifies the proof before sending HandshakeComplete

Because the proof covers the DH shared secret, an attacker doing MITM gets a different shared secret on each side and cannot forge a valid proof without knowing the password. Wrong or missing passwords are rejected with a clear error.

Connection fingerprint (always on)

After every handshake, both sides independently compute SHA-256(shared_secret)[0..3] — a 6-character hex string. It is:

  • Logged in both terminals: Handshake complete (fingerprint: a3f2b1)
  • Shown in the web UI toolbar in amber next to the connection status badge

Users can compare the fingerprint out-of-band (Telegram, phone call, etc.) to confirm no one is in the middle — even without a password.

Testing

  • Added password option to DriftProcess integration test helper
  • Three new test cases: correct password connects, wrong password is rejected, missing password is rejected