v5.6 batch: signed releases + stronger passwords enforced + relay address-proof
The everyone-must-update release. Four coordinated changes, each from the security discussion Ed approved 2026-07-27, plus the remembered-apps polish: 1. SIGNED RELEASES. build-release.ps1 now signs the release zip (ECDSA P-256 / SHA-256, --sign-update verb) with a private key that lives ONLY at Ed's chosen location outside the repo; the matching public key is embedded (UpdateSignature) and the updater REFUSES any release whose .sig asset is missing or does not verify - a compromised GitHub account can no longer ship code to users. The signing verb self-checks against the embedded key so a key/embed mismatch fails the pipeline, and the gate proves the on-disk key matches the embed when present. 2. STRONGER PASSWORDS, ENFORCED (BREAKING). PBKDF2 raised 100k -> 600k (both peers must derive the same key, so 5.6 cannot stream with pre-5.6 AT ALL - release notes lead with it). New PasswordStrength rule (>= 8 chars, not an infamous password) enforced at EVERY door: both password dialogs block weak NEW entries with concrete plain-English advice; the streaming gate walks an existing weak password through strengthening; and ForPlainPassword - the single derivation choke-point shared with the service - refuses weak outright, so no path streams on a guessable password. Headless service logs the why. Per Ed: painful once, and this coordinated-update release is the cheapest moment it will ever have. 3. RELAY ADDRESS-PROOF (watch-only). The relay sends every new client address a random cookie and marks it verified when echoed - a forged source address can never echo, killing the reflection attack. 5.6 clients echo automatically (AddrCheck type 10, verbatim, self-limiting); the relay ships watch-only (logs would-blocks) until the fleet updates, then one flag (--require-addr-check) enforces. Per-IP entry cap (4) enforced immediately. Relay changes are committed but NOT deployed to the Pi - they ride the v5.6 release moment. 4. Remembered-apps empty state teaches its lifecycle + manual sentence; About/ release notes written; version bumped to 5.6. New gate steps: signing round-trip/tamper/wrong-key/embed-match; password rules incl. the exact "Games" case; AddrCheck verbatim echo. Gate 69/69. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -78,7 +78,38 @@ internal static class ProfilePasswordManagerDialog
|
||||
rows.Add((title, current, box));
|
||||
}
|
||||
|
||||
var okButton = new Button { Text = "&OK", AutoSize = true, DialogResult = DialogResult.OK };
|
||||
var okButton = new Button { Text = "&OK", AutoSize = true };
|
||||
// OK validates by hand (no auto-close DialogResult): every CHANGED, non-empty entry passes
|
||||
// the same strength gate as the single-password dialog — one rule at every door. Unchanged
|
||||
// entries always pass (an old weak password is grandfathered until the day it's changed).
|
||||
okButton.Click += (_, _) =>
|
||||
{
|
||||
foreach (var (title, original, box) in rows)
|
||||
{
|
||||
var entered = box.Text.Trim();
|
||||
if (entered.Length > 0
|
||||
&& !string.Equals(entered, original, StringComparison.Ordinal)
|
||||
&& PasswordStrength.Critique(entered) is { } advice)
|
||||
{
|
||||
var page = new TaskDialogPage
|
||||
{
|
||||
Caption = "Choose a stronger password",
|
||||
Heading = $"The new password for “{title}” is too easy to guess",
|
||||
Text = advice,
|
||||
Icon = TaskDialogIcon.Warning,
|
||||
Buttons = { TaskDialogButton.OK },
|
||||
DefaultButton = TaskDialogButton.OK,
|
||||
AllowCancel = true,
|
||||
};
|
||||
TaskDialog.ShowDialog(dialog, page);
|
||||
box.Focus();
|
||||
box.SelectAll();
|
||||
return;
|
||||
}
|
||||
}
|
||||
dialog.DialogResult = DialogResult.OK;
|
||||
dialog.Close();
|
||||
};
|
||||
var cancelButton = new Button { Text = "&Cancel", AutoSize = true, DialogResult = DialogResult.Cancel };
|
||||
var buttons = new FlowLayoutPanel { Dock = DockStyle.Bottom, FlowDirection = FlowDirection.RightToLeft, AutoSize = true, Padding = new Padding(8) };
|
||||
buttons.Controls.Add(okButton);
|
||||
|
||||
Reference in New Issue
Block a user