No Chat Reports (NCR) Crypto
The cryptography used to generate passwords and encrypted messages exactly as the No Chat Reports Mod for Minecraft does.
Example
use ;
let passphrase = b"secret"; // Setting in NCR
// "Hello, world!" sent as a message in chat:
let ciphertext = decode.unwrap;
let decrypted = decrypt_with_passphrase;
let decoded = decode_and_verify;
assert_eq!
How it works
From reading the Source Code on Github it becomes clear how the mod does encryption:
- You set a passphrase like "secret" in the UI
- The mod uses
PBKDF2WithHmacSHA1with a hardcoded salt and 65536 iterations to make your passphrase into a hash of 16 bytes. This process takes the longest - An Initialization Vector (IV) is generated from a random nonce value, and used in the encryption that follows
- The new hash becomes the key used for encrypting any messages you send with
AES-CFB8encryption - The ciphertext that comes from this encryption is appended to the nonce that was generated, and the final message
that is sent in Base64 encoding through the chat (note:
"#%"is added as a prefix to the message before encrypting)
Decrypting then is very similar, just in reverse:
- Decode the message from Base64 into raw bytes
- Get the nonce from the message and generate the IV again with it
- Generate the hash from the secret passphrase again, and use it as the key for the AES encryption
- If the decrypted message starts with
"#%", the rest is printed decrypted in the chat