Proposal: cryptography library (Crypto.*) — SHA-256, HMAC, secure random (save/leaderboard integrity) #19
Labels
No labels
area:ci
area:docs
area:input
area:net
area:rendering
area:repo
area:stdlib
area:tooling
area:types
cleanup
dx
priority:high
priority:low
priority:medium
proposal
status:in-progress
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: workshopsoft/ludic#19
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
A cryptography library for the handful of security-sensitive things games do:
secure hashing (SHA-256), HMAC/signatures, and secure random bytes. Kept separate
from the fast non-crypto
Hash.*library so nobody reaches for the wrong tool.Why it matters for game devs (occasionally)
tampering is detectable.
This is low priority because most games don't need it, and when they do it's
usually a narrow slice. Correctness matters a lot, so it deserves a careful,
unhurried implementation.
Proposed API (illustrative)
sha256(+ maybesha512,blake3),hmac_sha256,verify_hmac,random_bytes(OS CSPRNG), hex/base64 helpers.verify_hmac, not==).Considerations
standard algorithms only; lean on known-answer tests.
Ludic carefully or FFI to the OS crypto where acceptable (decide in the RFC).
(a client-side game can't keep secrets from its owner). Document honestly so
non-experts don't over-trust it.
Scope / acceptance
random_bytes, all with test vectors.Related: Hashing (non-crypto), UUID, networking, Filesystem (signed saves).
Done in
a4f1494(commit2ddf830).The cryptography library is complete:
Crypto.sha256), HMAC-SHA256 (Crypto.hmac_sha256), and constant-timeverify_hmacwere already in place; this adds the OS CSPRNG surface —Crypto.random_bytes(n)/random_hex(n)(reading/dev/urandom, returned as hex since astrcan't hold NUL) andCrypto.random_u32()— plus a standard base64 encoder (Crypto.base64, RFC 4648).Random.*sim RNG).Acceptance:
random_bytes, all with test vectorsTests:
examples/library/crypto.ludicchecks SHA-256 (FIPS 180-4), HMAC-SHA256 (RFC 4231 case 2), and base64 (RFC 4648) against published vectors, plus the CSPRNG shape — wired intox test. Docs: per-symbol pages underdocs/language/crypto/.Not in scope for v1 (can be follow-ups if a concrete need appears): sha512/blake3, and an OS-native CSPRNG binding on wasm (the read degrades to zeroes there, documented).