drift v0.1.3
Security
MITM protection via password authentication and connection fingerprints.
Pure X25519 ECDH is fast and private, but without identity verification any attacker who can intercept the WebSocket connection can complete independent handshakes with both sides. v0.1.3 addresses this with two complementary mechanisms.
Password authentication (--password)
When both sides are started with --password <secret>, the handshake includes a challenge-response step after key exchange:
- Server generates a random 32-byte nonce and sends
AuthChallenge { nonce } - Client computes
HMAC-SHA256(password, nonce || shared_secret)and sendsAuthResponse { proof } - Server verifies the proof before sending
HandshakeComplete
Because the proof covers the DH shared secret, an attacker doing MITM gets a different shared secret on each side and cannot forge a valid proof without knowing the password. Wrong or missing passwords are rejected with a clear error.
Connection fingerprint (always on)
After every handshake, both sides independently compute SHA-256(shared_secret)[0..3] — a 6-character hex string. It is:
- Logged in both terminals:
Handshake complete (fingerprint: a3f2b1) - Shown in the web UI toolbar in amber next to the connection status badge
Users can compare the fingerprint out-of-band (Telegram, phone call, etc.) to confirm no one is in the middle — even without a password.
Testing
- Added
passwordoption toDriftProcessintegration test helper - Three new test cases: correct password connects, wrong password is rejected, missing password is rejected