aws / aws/aws-encryption-sdk-python

raise a better error when decryption of a message with an uncompressed EC point is attempted

Open
#21 2 comments 0 reactions 0 assignees View on GitHub
enhancement good first issue
Dominant language
Python
Stars
255
Forks
92
Avg merge
2d 17h
Merged PRs (30d)
2

Description

## Problem

In testing to verify what happens if a caller attempts to decrypt a file created by [mrcrypt](https://github.com/aol/mrcrypt), I realized that if you attempt to decrypt a message that was written with an uncompressed EC point (note: this is not supported under the AWS Encryption SDK spec), you get a very unhelpful error.

```
$ mrcrypt encrypt alias/exampleKey test_plaintext -r us-west-2
$ python
>>> import aws_encryption_sdk
>>> mkp = aws_encryption_sdk.KMSMasterKeyProvider()
>>> with open('test_plaintext.encrypted', 'rb') as f:
... ct = f.read()
...
>>> aws_encryption_sdk.decrypt(source=ct, key_provider=mkp)
No handlers could be found for logger "aws_encryption_sdk.streaming_client"
Traceback (most recent call last):
File "", line 1, in
File "/Users/bullocm/tmp/mrt/lib/python2.7/site-packages/aws_encryption_sdk/__init__.py", line 121, in decrypt
plaintext = decryptor.read()
File "/Users/bullocm/tmp/mrt/lib/python2.7/site-packages/aws_encryption_sdk/streaming_client.py", line 201, in read
self._prep_message()
File "/Users/bullocm/tmp/mrt/lib/python2.7/site-packages/aws_encryption_sdk/streaming_client.py", line 687, in _prep_message
self._header, self.header_auth = self._read_header()
File "/Users/bullocm/tmp/mrt/lib/python2.7/site-packages/aws_encryption_sdk/streaming_client.py", line 719, in _read_header
decryption_materials = self.config.materials_manager.decrypt_materials(request=decrypt_materials_request)
File "/Users/bullocm/tmp/mrt/lib/python2.7/site-packages/aws_encryption_sdk/materials_managers/default.py", line 149, in decrypt_materials
encryption_context=request.encryption_context
File "/Users/bullocm/tmp/mrt/lib/python2.7/site-packages/aws_encryption_sdk/materials_managers/default.py", line 129, in _load_verification_key_from_encryption_context
encoded_point=encoded_verification_key
File "/Users/bullocm/tmp/mrt/lib/python2.7/site-packages/aws_encryption_sdk/internal/crypto/authentication.py", line 159, in from_encoded_point
compressed_point=base64.b64decode(encoded_point)
File "/Users/bullocm/tmp/mrt/lib/python2.7/site-packages/aws_encryption_sdk/internal/crypto/elliptic_curve.py", line 182, in _ecc_public_numbers_from_compressed_point
x, y = _ecc_decode_compressed_point(curve, compressed_point)
File "/Users/bullocm/tmp/mrt/lib/python2.7/site-packages/aws_encryption_sdk/internal/crypto/elliptic_curve.py", line 140, in _ecc_decode_compressed_point
y_order = y_order_map[raw_y]
KeyError: '\x04'
```

## Solution
Catch appropriate errors in `internal.crypto.elliptic_curve._ecc_decode_compressed_point` and raise `NotSupportedError('Uncompressed points are not supported')`

Contributor guide

Open the contributing guide

Research direction

Start in internal/crypto/elliptic_curve.py at _ecc_decode_compressed_point and review how invalid point prefixes are handled. Reproduce the decryption example or inspect the shown traceback, then verify that an uncompressed point produces NotSupportedError with the requested message instead of KeyError.

Written by the indexing model from the issue text.

Assessment

Tech stack
cryptography, python
Domain
cryptography
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.