Encrypts using AES GCM for data with limited visibility and long rest

This is the third iteration of my venture on creating an encryption/decryption solution. I asked a question here, which led to this question here, which led to this answer here, which led me to introducing Bouncy Castle into my solution to gain better security under the circumstances and application requirements.

Requirements: To encrypt and decrypt a string using AES 256 with a password/key (stored in web.config) in an ASP.net application.

History: If you follow the above links you’ll find that I originally tried to stick with the core .net provided solutions without the inclusion of any additional libraries. This requirement has changed and I’ve added Bouncy Castle to my solution.

Thanks to @SEJPM regularly pointing me in the right direction I decided to implement AES GCM and ditch my previous attempts.

I found this example here from @jbtule who seems to have a pretty good handle on things, and honestly I didn’t change a thing other than convert it to VB. However, based on previous suggestions given to me to use Argon2, I read that Bouncy Castle supports this now but I’m currently uncertain as how to properly implement it.

Although my code is essentially a copy @jbtule’s original post on CodeReview, that was 6 years ago.

So based on the fact that I pull the encryption key/pass from web.config and I need simple encrypt/decrypt, how does this solution stack up?

Usage:

Dim password = RetrieveFromWebConfig() Dim plainText = "Hello World" Dim encrypted = SimpleEncryptWithPassword(plainText, password) Dim decrypted = SimpleDecryptWithPassword(encrypted, password) 

Code:

Imports System Imports System.IO Imports System.Text Imports Org.BouncyCastle.Crypto Imports Org.BouncyCastle.Crypto.Engines Imports Org.BouncyCastle.Crypto.Generators Imports Org.BouncyCastle.Crypto.Modes Imports Org.BouncyCastle.Crypto.Parameters Imports Org.BouncyCastle.Security  Namespace Utilities.Encryption     Public Class Aesgcm         Public Shared ReadOnly Random As SecureRandom = New SecureRandom()         Public Shared ReadOnly NonceBitSize As Integer = 128         Public Shared ReadOnly MacBitSize As Integer = 128         Public Shared ReadOnly KeyBitSize As Integer = 256         Public Shared ReadOnly SaltBitSize As Integer = 128         Public Shared ReadOnly Iterations As Integer = 10000         Public Shared ReadOnly MinPasswordLength As Integer = 12           Shared Function SimpleEncryptWithPassword(secretMessage As String, password As String, ByVal Optional nonSecretPayload As Byte() = Nothing) As String             If String.IsNullOrEmpty(secretMessage) Then Throw New ArgumentException("Secret Message Required!", "secretMessage")             Dim plainText = Encoding.UTF8.GetBytes(secretMessage)             Dim cipherText = SimpleEncryptWithPassword(plainText, password, nonSecretPayload)             Return Convert.ToBase64String(cipherText)         End Function          Shared Function SimpleDecryptWithPassword(encryptedMessage As String, password As String, ByVal Optional nonSecretPayloadLength As Integer = 0) As String             If String.IsNullOrWhiteSpace(encryptedMessage) Then Throw New ArgumentException("Encrypted Message Required!", "encryptedMessage")             Dim cipherText = Convert.FromBase64String(encryptedMessage)             Dim plainText = SimpleDecryptWithPassword(cipherText, password, nonSecretPayloadLength)             Return If(plainText Is Nothing, Nothing, Encoding.UTF8.GetString(plainText))         End Function          Shared Function SimpleEncrypt(secretMessage As Byte(), key As Byte(), ByVal Optional nonSecretPayload As Byte() = Nothing) As Byte()             If key Is Nothing OrElse key.Length <> KeyBitSize / 8 Then Throw New ArgumentException($  "Key needs to be {KeyBitSize} bit!", "key")             If secretMessage Is Nothing OrElse secretMessage.Length = 0 Then Throw New ArgumentException("Secret Message Required!", "secretMessage")             nonSecretPayload = If(nonSecretPayload, New Byte() {})             Dim nonce = New Byte(CInt(NonceBitSize / 8 - 1)) {}             Random.NextBytes(nonce, 0, nonce.Length)             Dim cipher = New GcmBlockCipher(New AesEngine())             Dim parameters = New AeadParameters(New KeyParameter(key), MacBitSize, nonce, nonSecretPayload)             cipher.Init(True, parameters)             Dim cipherText = New Byte(cipher.GetOutputSize(secretMessage.Length) - 1) {}             Dim len = cipher.ProcessBytes(secretMessage, 0, secretMessage.Length, cipherText, 0)             cipher.DoFinal(cipherText, len)              Using combinedStream = New MemoryStream()                  Using binaryWriter = New BinaryWriter(combinedStream)                     binaryWriter.Write(nonSecretPayload)                     binaryWriter.Write(nonce)                     binaryWriter.Write(cipherText)                 End Using                  Return combinedStream.ToArray()             End Using         End Function          Shared Function SimpleDecrypt(encryptedMessage As Byte(), key As Byte(), ByVal Optional nonSecretPayloadLength As Integer = 0) As Byte()             If key Is Nothing OrElse key.Length <> KeyBitSize / 8 Then Throw New ArgumentException($  "Key needs to be {KeyBitSize} bit!", "key")             If encryptedMessage Is Nothing OrElse encryptedMessage.Length = 0 Then Throw New ArgumentException("Encrypted Message Required!", "encryptedMessage")              Using cipherStream = New MemoryStream(encryptedMessage)                  Using cipherReader = New BinaryReader(cipherStream)                     Dim nonSecretPayload = cipherReader.ReadBytes(nonSecretPayloadLength)                     Dim nonce = cipherReader.ReadBytes(CInt(NonceBitSize / 8))                     Dim cipher = New GcmBlockCipher(New AesEngine())                     Dim parameters = New AeadParameters(New KeyParameter(key), MacBitSize, nonce, nonSecretPayload)                     cipher.Init(False, parameters)                     Dim cipherText = cipherReader.ReadBytes(encryptedMessage.Length - nonSecretPayloadLength - nonce.Length)                     Dim plainText = New Byte(cipher.GetOutputSize(cipherText.Length) - 1) {}                      Try                         Dim len = cipher.ProcessBytes(cipherText, 0, cipherText.Length, plainText, 0)                         cipher.DoFinal(plainText, len)                     Catch unusedInvalidCipherTextException1 As InvalidCipherTextException                         Return Nothing                     End Try                      Return plainText                 End Using             End Using         End Function          Shared Function SimpleEncryptWithPassword(secretMessage As Byte(), password As String, ByVal Optional nonSecretPayload As Byte() = Nothing) As Byte()             nonSecretPayload = If(nonSecretPayload, New Byte() {})             If String.IsNullOrWhiteSpace(password) OrElse password.Length < MinPasswordLength Then Throw New ArgumentException($  "Must have a password of at least {MinPasswordLength} characters!", "password")             If secretMessage Is Nothing OrElse secretMessage.Length = 0 Then Throw New ArgumentException("Secret Message Required!", "secretMessage")             Dim generator = New Pkcs5S2ParametersGenerator()             Dim salt = New Byte(CInt(SaltBitSize / 8 - 1)) {}             Random.NextBytes(salt)             generator.Init(PbeParametersGenerator.Pkcs5PasswordToBytes(password.ToCharArray()), salt, Iterations)             Dim key = CType(generator.GenerateDerivedMacParameters(KeyBitSize), KeyParameter)             Dim payload = New Byte(salt.Length + nonSecretPayload.Length - 1) {}             Array.Copy(nonSecretPayload, payload, nonSecretPayload.Length)             Array.Copy(salt, 0, payload, nonSecretPayload.Length, salt.Length)             Return SimpleEncrypt(secretMessage, key.GetKey(), payload)         End Function          Shared Function SimpleDecryptWithPassword(encryptedMessage As Byte(), password As String, ByVal Optional nonSecretPayloadLength As Integer = 0) As Byte()             If String.IsNullOrWhiteSpace(password) OrElse password.Length < MinPasswordLength Then Throw New ArgumentException($  "Must have a password of at least {MinPasswordLength} characters!", "password")             If encryptedMessage Is Nothing OrElse encryptedMessage.Length = 0 Then Throw New ArgumentException("Encrypted Message Required!", "encryptedMessage")             Dim generator = New Pkcs5S2ParametersGenerator()             Dim salt = New Byte(CInt(SaltBitSize / 8 - 1)) {}             Array.Copy(encryptedMessage, nonSecretPayloadLength, salt, 0, salt.Length)             generator.Init(PbeParametersGenerator.Pkcs5PasswordToBytes(password.ToCharArray()), salt, Iterations)              Dim key = CType(generator.GenerateDerivedMacParameters(KeyBitSize), KeyParameter)             Return SimpleDecrypt(encryptedMessage, key.GetKey(), salt.Length + nonSecretPayloadLength)         End Function     End Class End Namespace 

google services has stopped wont stop long enough for me to fix the problem cant even get into my settings

google services keeps looping gives me no time to fix due to it just keeps forcing me back to same looping message cant even get into my settings for long enough to repair because it just throws me back to the same looping error screen

How long does it take to use first aid to save a dying character?

In the PHB, it says that a character can perform first aid in order to stabilize a dying character. The Heal DC is 15 and if the character makes it, then the character immediately stops losing HP and is stabilized. This takes one standard action. (Given that you get a move and a standard action in one round and one round is 6 seconds, then this action takes approximately 3 seconds to perform.)

Yet on page 138 under “The Combat Round”, it says

Anything a person could reasonably do in 6 seconds, your character can do in one round.

My issue is the discrepancy here. You cannot reasonably stabilize someone and stop them from losing blood, etc. in 3 seconds; it’s impossible without some form of magical aid. So how is it a person can perform a Heal check in 3 seconds and stabilize a dying person, when doing so is unreasonable?

Why does google use 1000 char long image links?

When I copy an image address from the gallery on google.fr/images it copies this to my clipboard, why?

 



??? it’s a bit overkill for a hyperlink? what is google doing? I know that if i click on it again i get the real link, but it’s a new thing from google, it’s weird!

How long does one remain sudo in terminal? [duplicate]

This question already has an answer here:

  • How often is the password asked for sudo commands? Where can I set it up? 3 answers

When you run a command as sudo in terminal, you will have the sudo rights for some time. This means you can run several sudo commands right after another but you only have to enter the password for the very first command, for example in

sudo apt-get update sudo apt-get dist-upgrade 

you only have to enter the sudo-password for the first line but not for the second one, if you execute the second command immediately after the first one.

If you leave the terminal open and wait for some time, say 5 hours, and you want to run another sudo command, you are asked for the password again (which makes a lot of sense, for security reasons, for example). So, I was wondering for how long is one granted sudo rights after entering the password? Moreover, is there a way to increase or decrease the time until you lose sudo-rights after entering the password?

Why does it take so long to proof optimality when wam-starting from optimal solution

So I’m solving bigger instances of some binary-linear-program using cplex. The formulations of the problem I am using is integer friendly, meaning nearly all of my instances can be solved at the root node. Additionally I have a pretty good heuristic for calculating solutions. The heuristic is quite fast and nearly always gives the globally optimal solution.

When combining cplex with the heuristic I do not achieve the performance gains I expected. I feed the globally optimal solution to cplex as a “warm-start-solution”, but it still takes quite some time for cplex to proof its optimality (cplex chooses the dual-simplex for the relaxation).

I might lack some theoretical understanding, but why can’t the dual-simplex just build a basis for the supplied optimal solution and show that there is nothing else to do?

How do I determine if the rules for a long jump or high jump are applicable for Monks?

Inspired by this question

At 9th level, Monks can:

…you gain the ability to move along vertical surfaces and across liquids on your turns without falling during the move.

I interpret this to mean that the Monk can simply treat horizontal and vertical movement as the same for the purposes of determining how far they can move on their turn.

Suppose a 10th level Monk with 50′ of movement is in front of a 20′ tall building. 10′ above the building is a flying opponent.

      O      -|- (pitiable fool)      / \ 10' ------      |      | 20'  |     O bldg.|    \|/ (Mr. T in Monk form)      |____/ \ 

Can the monk simply run up the wall and perform a horizontal long jump to reach the flying opponent (assume Monk’s strength is at least 10)? This seems appropriate as from the Monk’s point of view, they would be traveling in a horizontal line towards their opponent and their class feature suggests that for the duration of their turn gravity seems to be effectively turned off.

Alternately, are the high jump rules applicable because from the overall point of view, the Monk’s movement is vertical.

Items with long title in Android

In an Android application, I have a “Grid Layout” with fixed size cells for describing Three-line items:

mockup

download bmml source – Wireframes created with Balsamiq Mockups

Number of columns and rows in Grid depend to the device dimensions. Also above items (boxes) will created by users and this may cause a problem:

What we have to do if a user enter a long title which exceeds bound of item? Of course we can do:

  1. ellipsis title
  2. limit input characters of title
  3. break long title text into two lines
  4. use “list” instead of grid; but it cause empty/blank spaces on “tablets” around items

What is the best choice?