What happens?
An encrypted canary is stored in the database header of an encrypted file, to check whether the correct key is used to decrypt a database. Currently, we use AES-GCM with a constant IV to en- and decrypt, without storing and checking the tag. This is not NIST-compliant.
To Reproduce
n/a
OS:
MacOS
DuckDB Version:
1.4.2
DuckDB Client:
CLI
Hardware:
n/a
Full Name:
Lotte Felius
Affiliation:
DuckDB Labs
Did you include all relevant configuration (e.g., CPU architecture, Linux distribution) to reproduce the issue?
Did you include all code required to reproduce the issue?
Did you include all relevant data sets for reproducing the issue?
No - Other reason (please specify in the issue body)
What happens?
An encrypted canary is stored in the database header of an encrypted file, to check whether the correct key is used to decrypt a database. Currently, we use AES-GCM with a constant IV to en- and decrypt, without storing and checking the tag. This is not NIST-compliant.
To Reproduce
n/a
OS:
MacOS
DuckDB Version:
1.4.2
DuckDB Client:
CLI
Hardware:
n/a
Full Name:
Lotte Felius
Affiliation:
DuckDB Labs
Did you include all relevant configuration (e.g., CPU architecture, Linux distribution) to reproduce the issue?
Did you include all code required to reproduce the issue?
Did you include all relevant data sets for reproducing the issue?
No - Other reason (please specify in the issue body)