Git Product home page Git Product logo

aescrypt-android's Introduction

AESCrypt-Android

Android Arsenal

Simple API to perform AES encryption on Android with no dependancies. This is the Android counterpart to the AESCrypt library Ruby and AESCrypt-ObjC created by Gurpartap Singh. It used the same weak :'( security defaults i.e Blank IV noted below.

For compatiblity with AESCrypt, AESCrypt-Android has the same defaults namely:

  • 256-bit AES key
  • CBC mode
  • PKCS7Padding
  • Blank/Empty IV (default)*

*Using CBC with the default blank IV is vulnerable. This has been left in for compatibility with AESCrypt implementations. See Adv method for providing your own IV. If you don't need to be compatable with AESCrypt then look at java-aes-crypto it's API is just as simple and generates more secure keys.

Dependency

Download from Maven Central (.aar)

or

dependencies {
  compile 'com.scottyab:aescrypt:0.0.1'
}

Usage

Encrypt

String password = "password";
String message = "hello world";	
try {
    String encryptedMsg = AESCrypt.encrypt(password, message);
}catch (GeneralSecurityException e){
    //handle error
}

Decrypt

String password = "password";
String encryptedMsg = "2B22cS3UC5s35WBihLBo8w==";
try {
    String messageAfterDecrypt = AESCrypt.decrypt(password, encryptedMsg);
}catch (GeneralSecurityException e){
     //handle error - could be due to incorrect password or tampered encryptedMsg
}

Recommended Advanced usage

Please if you are going to use this library provide your own key, and use a different IV per message that you encrypt..

AESCrypt.encrypt(final SecretKeySpec key, final byte[] iv, final byte[] message)

AESCrypt.decrypt(final SecretKeySpec key, final byte[] iv, final byte[] decodedCipherText)

Note: for flexibility these 'adv' methods don't provide BASE64 encoding/decoding.

Debugging/Logging

To enable logging simple change switch on the logging flag as shown below.

AESCrypt.DEBUG_LOG_ENABLED = true;

Remember to disable in Live, recommend the below snippet if possible

if (BuildConfig.DEBUG) {
    AESCrypt.DEBUG_LOG_ENABLED = true;
}

To be honest it's a strech to call this a library given it's only a single util class, but I created as went through a ton of pain working out the conpatible settings for AESCrypt. I hope this will save some one time in the future.

Contributing

I welcome pull requests, issues and feedback.

  • Fork it
  • Create your feature branch (git checkout -b my-new-feature)
  • Commit your changes (git commit -am 'Added some feature')
  • Push to the branch (git push origin my-new-feature)
  • Create new Pull Request

Licence

Copyright (c) 2014 Scott Alexander-Bown

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

aescrypt-android's People

Contributors

doridori avatar scottyab avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

aescrypt-android's Issues

How to use aes256 mode?

I use AESCrypt.encrypt("123456","123456") and I got "LK09ZUQfjEWnBhyah8VNXg=="
but the result should be "U2FsdGVkX1/bIqQCoW3eTfBoynP0mswP1PE6HM97jTk=" .
What's the problem?

Use less Library Delete this Shit

After apk decompiler it clearly show all my string (jsoneditoronline.org)
ex: this.encryptedMsg = AESCrypt.encrypt("url", "myurl");

Then why this useless library.. don't wast developer time .. just delete thus shit library

dont call this shit encrypt and decrypt

Encryption result of AESCrypt-Android library differs from result in php?

According to the usage example, using password = password and message = hello world results in the encrypted message 2B22cS3UC5s35WBihLBo8w==

However in php using the same password and message following the snippet here results in the encrypted message lMwL6ztvVavgsTu7NJE/kw== which is different.

See complete php code snippet here

<!DOCTYPE html>
<head>
  <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
</head>

<body>
 <!-- following this snippet<br>
      https://www.urbaninsight.com/2012/06/13/encrypt-and-decrypt-strings-php
 -->

 <?php
  $string = "hello world";
  $password = "password";
  $method = "aes-256-cbc";

  $encrypted = openssl_encrypt($string, $method, $password);
  echo "ENCRYPT:<br>$string<br>$password<br>$encrypted<br><br>";

  $decrypted = openssl_decrypt($encrypted, $method, $password);
  echo "DECRYPT:<br>$encrypted<br>$password<br>$decrypted";
 ?>

 <!-- result: lMwL6ztvVavgsTu7NJE/kw==
  -->

 </body>
</html>

Is the AESCrypt-Android library not compatible with php or is there something, I'm overseeing currently?
Thank you in advance!
Taifun

IV must be 16 bytes long

Hello,

Im getting (IV must be 16bytes long) when using the advance mode.

My encryptedText = "HE9257Ykdrnb7zZTbNYLcLNzsg24t2aEftUZ7Tr0BU0="
My IV = "618wNQX6K3k2343c" //My IV is 16byte long

I base 64 decode both using Base64.decode(encryptedText, Base64.NO_WRAP)
and Base64.decode(IV, Base64.NO_WRAP)
then pass in (SecretKeySpec, byte[] IV, byte[] encryptedText ) as parameter for advance mode,
but gave me an error (IV must be 16 bytes long).

NULL POINTER EXCEPTION :

Encryption and decryption is not worked on some devices. It gives null pointer instead of encrypted or decrypted string.

PHP Equivalent

I would like to know if there is a php equivalent of this library for decrypting a string encrypted in android. Thanks

Plain Text Error

Hello, Am using the library for a messaging app am working on. Before using the library messages are sent in plain text so after adding the library the decrypt message crashes the app for those old messages. Since the wrapped in the try catch block was expecting to catch the error for plain text.
Need help please. :(

stack trace below

Fatal Exception: java.lang.IllegalArgumentException
Fatal Exception: java.lang.IllegalArgumentException: bad base-64
at android.util.Base64.decode(Base64.java:161)
at android.util.Base64.decode(Base64.java:136)
at android.util.Base64.decode(Base64.java:118)
at com.scottyab.aescrypt.AESCrypt.decrypt(AESCrypt.java:124)

Crashing if invalid BASE64 String Given

java.lang.IllegalArgumentException: bad base-64

in this line :
byte[] decodedCipherText = Base64.decode(base64EncodedCipherText, Base64.NO_WRAP);

This occurs when base64EncodedCipherText is not a proper BASE64 value .
Write something to check for a proper BASE64 and then pass it to the function.

Encryption result is different on Android and IOS

Hello,

I am using this library in my android project and its counter part https://github.com/Gurpartap/aescrypt in ios project. I am encrypting same text with same encryption key, but it is giving me different results on ios and android.

I am using this key : 25c35734b1ef623ca2a7f730cf2fea8b790739ba

String to encrypt is : Password

Encrypted String IOS : W3LyAxKq2+QdDBfKUGVgTg==
Encrypted String Android : zdgSimKva1jblici7F8DGw==

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.