Security: reject insecure default channel_secret, add input validation - #1
Open
devin-ai-integration[bot] wants to merge 1 commit into
Open
devin-ai-integration[bot] wants to merge 1 commit into
devin-ai-integration[bot] wants to merge 1 commit into
Conversation
- MeshCore_Dynamic_Interface: replace all-zeros default channel_secret with startup validation that refuses to initialize if the secret is missing, empty, or set to the known insecure default. Also adds format (hex) and length (16 bytes) validation. - MeshCore_Channel_Interface: replace hardcoded default channel_secret (c4d2b6c8254e3b11200f57e95dcb1197) with the same startup validation. Updates docstring config examples to use a placeholder instead of a real secret value. Enhances SSL-disabled warning to explicitly mention MITM risk. These changes prevent nodes from silently running with publicly-known encryption keys, which would allow any eavesdropper to decode and inject packets on the mesh. Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Author
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Both
MeshCore_Dynamic_InterfaceandMeshCore_Channel_Interfacepreviously shipped hardcoded defaultchannel_secretvalues (all-zeros andc4d2b6c8254e3b11200f57e95dcb1197respectively). Any node that omitted the config key silently used a publicly-known encryption key — traffic was effectively readable and injectable by anyone with the source code.Changes:
__init__now raisesValueErrorat startup ifchannel_secretis missing, empty, or matches a known insecure default — the interface refuses to come online rather than silently running unencrypted:Adds format + length validation (
bytes.fromhex()+ 16-byte check) so malformed secrets fail fast with a clear error instead of crashing later inset_channel().Enhances the SSL-disabled warning in
MeshCore_Channel_Interfaceto explicitly mention MITM risk.Replaces hardcoded secret in docstring config examples with
<your-32-hex-char-secret>placeholder.Not a security issue (confirmed clean): no SQL, no
eval/execon user input, no exposed HTTP endpoints, no pickle deserialization, assembly buffers are TTL-bounded.Link to Devin session: https://app.devin.ai/sessions/4bbb0eb40d024e8f9661e57de3075684
Requested by: @comms-engineer