Skip to content

Conversation

@jentfoo
Copy link
Contributor

@jentfoo jentfoo commented Nov 4, 2024

This change is motivated from the CodeQL result: https://github.com/opentdf/java-sdk/security/code-scanning/1

Although that use of a static IV is deliberate, it helped highlight that we should ensure that there is no reuse of the IV when encrypting the data.

In addition it was found that there were two places the key was logged, due to the sensitivity of the key this has been removed.

This change is motivated from the CodeQL result: https://github.com/opentdf/java-sdk/security/code-scanning/1

Although that use of a static IV is deliberate, it helped highlight that we should ensure that there is no reuse of the IV when encrypting the data.

In addition it was found that there were two places the key was logged, due to the sensitivity of the key this has been removed.
@jentfoo jentfoo self-assigned this Nov 4, 2024
@jentfoo jentfoo requested review from a team as code owners November 4, 2024 21:57
@sonarqubecloud
Copy link

sonarqubecloud bot commented Nov 4, 2024

@jentfoo jentfoo merged commit 6301d32 into main Nov 5, 2024
7 checks passed
@jentfoo jentfoo deleted the jent/nanoTDF_key_hardening branch November 5, 2024 16:45
mkleene pushed a commit that referenced this pull request Feb 6, 2025
🤖 I have created a release *beep* *boop*
---


<details><summary>0.7.6</summary>

## [0.7.6](v0.7.5...v0.7.6)
(2025-02-06)


### Features

* Add assertion verification
([#216](#216))
([e0f8caf](e0f8caf))
* **cmdline:** assertions cli support
([#204](#204))
([3325114](3325114))
* **sdk:** Add and expose tamper error types
([#187](#187))
([b4f95e6](b4f95e6))
* **sdk:** adds Collections API
([#212](#212))
([1ee1367](1ee1367))


### Bug Fixes

* Correct null assertions when deserializing
([#211](#211))
([b075194](b075194))
* incorrect isStreamable serialized name
([#210](#210))
([32825b0](32825b0))
* NanoTDF secure key from debug logging and iv conflict risk
([#208](#208))
([6301d32](6301d32))
* **sdk:** deserialize object statement values correctly
([#219](#219))
([c513e8c](c513e8c))
* **sdk:** Fuzz testing and protocol fixes
([#214](#214))
([cf6f932](cf6f932))
* **sdk:** group splits with empty/missing split IDs together
([#217](#217))
([0f47702](0f47702))
* **sdk:** remove hex encoding
([#213](#213))
([e076d11](e076d11))
* **sdk:** uses offset for ByteBuffer array offset
([#209](#209))
([0d6e761](0d6e761))
* Use reusable start-additional-kas workflow
([#215](#215))
([cb6f757](cb6f757))
</details>

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants