Eiji

Eiji

Security: HTTPS, WSS, PFS and E2EE with Phoenix framework

At start some definitions:

  1. HTTPS (is a protocol for secure communication over a computer network which is widely used on the Internet) - see HTTPS Wikipedia article
  2. WSS (secured WebSocket protocol) - see WebSocket Wikipedia article
  3. PFS (is a property of secure communication protocols in which compromise of long-term keys does not compromise past session keys) - see Perfect Forward Secrecy Wikipedia article.
  4. E2EE (a cryptographic paradigm involving uninterrupted protection of data traveling between two communicating parties) - see End-to-end encryption Wikipedia article

Summary:

  1. HTTPS, WSS protocols can be set in configuration
  2. PFS can be set in configuration too and need more attention (ciphers, SSL version)
  3. E2EE - to setup this we need choose algorithm(s) to generate, export, import, encrypt and decrypt for Web Cryptography API; time between generate new keys depends on what is used in application

Helpful sources:

  1. Mozilla wiki article describes SSL configuration and splits it by client support.
  2. SSL configuration could be set in standard nginx way or in cowboy/phoenix configuration.
  3. An examples of using Web Cryptography API

Most Liked

f0rest8

f0rest8

Maybe I shouldn’t revive this topic (in that case, sorry!), but I believe figuring out ways to make it easier to implement encryption in Elixir and Phoenix applications is more relevant, and pertinent, than ever.

The following library is a good choice to use if attempting to implement encryption in your Elixir/Phoenix applications:

Sodium (libsodium) is a fork of NaCl, a trusted library by security experts. By using enacl (libsodium/NaCl) you set yourself up to not accidentally make a mistake that renders your security not as secure as you think. The PragProg book, Practical Security, also recommends the library for encryption for this very reason.

Additionally, this is an interesting take by Badu on implementing both symmetric encryption and asymmetric encryption (along with user derived keys).

Symmetric Encryption
In regard to symmetric encryption, dwyl made a great Phoenix encryption example that I’ve been testing and works exceptionally well from a developer and client perspective.

It is worth noting however, that the person (or company/people) with access to the encryption keys can theoretically decrypt the data. This is true of all symmetric encryption.

Asymmetric Encryption
Badu has two nice examples here with Elixir, Part III and Part IV.

Asymmetric encryption is commonly referred to as public-key cryptography. I don’t know of any other example in Elixir/Phoenix other than Badu’s.

End-to-End Encryption (E2EE)
The Signal Protocol set the bar here. Good news is that the IETF has a working group (MLS) developing a Messaging Layer Security architecture and protocol standard. In theory, it’ll be an excellent choice for anyone working to implement end-to-end encryption (especially for large groups).

I’ve been following their development: MLS GitHub, Datatracker.

E2EE tends to use combinations of asymmetric and symmetric encryption to make it all work.

I’m not aware of any current example offering end-to-end encryption with a Phoenix app. My initial thinking is that you can take guidance from Badu’s asymmetric encryption example and dwyl’s transparent symmetric encryption example to essentially create an end-to-end encrypted Phoenix app. It would work something like this:

  • password derived key → gives each person/user access to their data
    Since the password is hashed, only knowledge of someone’s password can ever decrypt their data. This ensures the company/person with access to the system cannot access a client’s key to decrypt their data (in theory).

  • transparently shared public keys → gives people the ability to share/edit data with each other
    This would work behind the scenes, transparently to the client, like how dwyl’s example works.

This is clearly not a finished thought, but the idea being that there may be a way to take a symmetric encryption example and combine it with Badu’s asymmetric example to deliver something close to end-to-end encryption in a Phoenix and Elixir app.

Other approaches
For instance, if you’re implementing video chat through Phoenix, over WebSockets, with authentication, using a peer-to-peer mesh architecture and STUN server, then your video chat is already end-to-end encrypted and avoids some of the known WebSocket security vulnerabilities.

I was able to achieve this by following the incredible guide by Jesse Herrick of Littlelines, then tying it into an existing authentication solution (phx_gen_auth for example).

This makes me think that, as mentioned 4 years ago, communication over channels would also be secured similarly provided you setup your Phoenix socket configuration to use :websocket and not :longpoll.

:blush::heart:

Nicd

Nicd

Phoenix has HTTPS and WSS support builtin, see http://www.phoenixframework.org/docs/configuration-for-ssl

For PFS I believe you need to configure your server to use specific key exchange algorithms (i.e. it’s not a matter of the certificate). I don’t know how to do that with Phoenix. Personally I terminate TLS with Nginx and proxy it to Phoenix.

HTTPS and WSS are end-to-end encrypted, one end being the client’s browser and the other end being the server.

For free certificates, take a look at https://letsencrypt.org/

Qqwy

Qqwy

TypeCheck Core Team

There are many different algorithms that are used for very different reasons.

Diffie-Helmann (which is indeed what DH stands for) lets two parties compute a shared secret. It does not do encryption/decryption itself, that’s just not what it is for. Indeed, usually DH is used to find a shared key, which is then used as encryption/decryption key in a symmetric cypher, such as AES or Blowfish.

ArrayBuffers are things that were added to JavaScript to allow easier (more efficient and less error-prone) manipulations of binary data. I am not entirely sure if the HTML5 WebSocket API (regardless of Phoenix) supports transferring such an object directly; it could very well be that it needs to be converted to either a binary file or a Base64 string.

Qqwy

Qqwy

TypeCheck Core Team

That completely depends on what it is used for in your application.
If you want to store encrypted data for an end-user, then he is in control of when a key is changed.

If you want to allow end-to-end encrypted communication between two parties, then it is best to use something like Ephemeral Diffie-Hellman (as it allows for perfect forward secrecy) where for each session a new key is generated.

Eiji

Eiji

@Qqwy: Ok, thx - here I summarize all info:

  1. HTTPS, WSS protocols are configurable
  2. WSS is already provided in above protocols
  3. PFS is configurable too and need more attention (ciphers, SSL version)
  4. E2EE - to setup this we need choose algorithm(s) to generate, export, import, encrypt and decrypt for Web Cryptography API; time between generate new keys depends on what is used in application

Mozilla wiki article describes SSL configuration and splits it by client support.
SSL configuration could be set in standard nginx way or in cowboy/phoenix configuration.
An examples of using Web Cryptography API

Where Next?

Popular in Wikis Top

yurko
Here are few pieces of (common) Linux knowledge that we use for reasonably small one server apps. We use Ubuntu but this should work for ...
New
axelson
With the new year I am looking at travel for this year and I’d love to base some travel around Elixir. So in the spirit of the 2017 threa...
New
axelson
This post is a wiki (feel free to hit the edit button near the bottom right of this post to add your own changes!) This post collects co...
239 45766 226
New
georgeguimaraes
Hi people, since the new year is coming, I’d like to plan my travels for events in 2017. So, what events (Elixir or FP related) that you...
New
Rich_Morin
I’d like to start a discussion of data serialization formats, in the context of Elixir. The rest of this note is a combination of persona...
New
anildigital
Here is list of plugins for different editors Sublime Text 3 — Elixir.tmbundle - https://github.com/elixir-editors/elixir-tmbundle/#co...
New
ibgib
Popular Elixir Packages List of popular Atom.io Elixir Packages. These can be installed via atom’s package center or a command line with ...
New
blackode
This is a wiki - anyone at Trust Level 1 or higher can help keep it updated. Elixir Pocket Syntax Uncommon Logical stuff of Elixir modul...
New
BartOtten
A wiki for Doom Emacs Doom is a configuration framework for GNU Emacs. It focuses on performance and customizability. It can be a founda...
New
blackode
Hi and Hello Every Elixirian. After Learning the Elixir basics, I struck then. I have no idea of how to put my Elixir Knowledge in pract...
New

Other popular topics Top

sorentwo
Hello! tl;dr Announcing Oban, an Ecto based job processing library with a focus on reliability and historical observability. After spen...
977 41022 311
New
vonH
In asking this question I am more interested about the expressiveness of the language itself and less concerned about the availability of...
New
openscript
Hello! Sorry for this astonishing simple question, but I’m really stuck. I try to set up the intellij-elixir plugin, but I don’t know ho...
New
joaquinalcerro
Hi there, I am working with Ecto-Postgresql and I need to call all of the records from a specific table but the table has 40,000 record...
New
malloryerik
Hi, this is for people who, like me, have had some friction using .html.heex templates in VSCode. The solution seems to be, in a hyphena...
New
KronicDeth
Elixir plugin for JetBrain’s IntelliJ Platform (including Rubymine) This is a plugin that adds support for Elixir to JetBrains IntelliJ...
289 35421 110
New
script
If I have a string “1000 cfu/ml” . I want to remove the characters and / and space . So the string is like this "1000" What is the ...
New
rms.mrcs
Hi, I need to transform a list of numbers into a map where the keys are the indexes and the values are the original values of the list....
New
qwerescape
Is there a way to get the call stack or stack trace at any point in the code? Not from exceptions, but an expression that returns how the...
New
fayddelight
I tried installing elixir 1.11.2 erlang 23.3.4 via asdf in my zsh shell. Enabled the versions locally and globally. When I list them ...
New

We're in Beta

About us Mission Statement