NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1384 most downloaded on npm
Port of TweetNaCl cryptographic library to JavaScript
Last release 7 years ago
no release in 18 months
Release timing varies
gaps range from 1 weeks to 1.7 years
Nearly every release is documented
notes for 24 of 24 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
25 releases · first in 2014
*IMPORTANT BUG FIX*. Due to a bug in calculating carry in modulo reduction that used bit operations on integers larger than 32 bits, nacl.sign or nacl
IMPORTANT BUG FIX. Due to a bug in calculating carry in
modulo reduction that used bit operations on integers larger than
32 bits, nacl.sign or nacl.sign.detached could have created
incorrect signatures.
This only affects signing, not verification.
Thanks to @valerini on GitHub for finding and reporting the bug.
Exported more internal undocumented functions for third-party projects that rely on low-level interface, (something users of TweetNaCl shouldn't care
Exported more internal undocumented functions for
third-party projects that rely on low-level interface,
(something users of TweetNaCl shouldn't care about).
One column per quarter.
v1.0.2
Compare
Rebuilt using newer version of Uglify-js.
Removed deprecation checks for nacl.util (moved to a separate package in v0.14.0).
🗝 🎉 🔐
No code changes
IMPORTANT! In previous versions, nacl.secretbox.open, nacl.box.open, and nacl.box.after returned false when opening failed (for example, when using incorrect key, nonce, or when input was maliciously or accidentally modified after encryption). This version instead returns null.
The usual way to check for this condition:
if (!result) { ... }
is correct and will continue to work.
However, direct comparison with false:
if (result == false) { ... }
it will no longer work and will not detect failure. Please check your code for this condition.
(nacl.sign.open always returned null, so it is not affected.)
Arguments type check now uses instanceof Uint8Array instead of Object.prototype.toString.
Removed deprecation checks for nacl.util (moved to a
separate package in v0.14.0).
Removed deprecation checks for the old signature API (changed in v0.10.0).
Improved benchmarking.
Removed deprecation checks for nacl.util (moved to a separate package in v0.14.0).
IMPORTANT! In previous versions, nacl.secretbox.open, nacl.box.open, and nacl.box.after returned false when opening failed (for example, when using incorrect key, nonce, or when input was maliciously or accidentally modified after encryption). This version instead returns null.
The usual way to check for this condition:
if (!result) { ... }
is correct and will continue to work.
However, direct comparison with false:
if (result == false) { ... }
it will no longer work and will not detect failure. Please check your code for this condition.
(nacl.sign.open always returned null, so it is not affected.)
Arguments type check now uses instanceof Uint8Array instead of Object.prototype.toString.
Removed deprecation checks for nacl.util (moved to a
separate package in v0.14.0).
Removed deprecation checks for the old signature API (changed in v0.10.0).
Improved benchmarking.
Fixed incomplete return types in TypeScript typings.
IMPORTANT! In previous versions, nacl.secretbox.open , nacl.box.open , and nacl.box.after returned false when opening failed (for example, when using incorrect key, nonce, or when input was maliciously or accidentally modified after encryption). This version instead returns null .
The usual way to check for this condition:
if (!result) { ... }
is correct and will continue to work.
However, direct comparison with false :
if (result == false) { ... }
it will no longer work and will not detect failure . Please check your code for this condition.
( nacl.sign.open always returned null , so it is not affected.)
Arguments type check now uses instanceof Uint8Array instead of Object.prototype.toString .
Removed deprecation checks for nacl.util (moved to a separate package in v0.14.0).
Removed deprecation checks for the old signature API (changed in v0.10.0).
Improved benchmarking.
Assets 2 Loading
There was an error while loading. Please reload this page .
All reactions
Added TypeScript type definitions (contributed by @AndSDev ).
The bug in the fast version of Poly1305 has been fixed and this version is back into nacl-fast.js. Thanks to @floodyberry for promptly responding and
The bug in the fast version of Poly1305 has been fixed and this version is back into nacl-fast.js. Thanks to @floodyberry for promptly responding and fixing it:
"The issue was not properly detecting if st->h was >= 2^130 - 5, coupled with [testing mistake] not catching the failure. The chance of the bug affecting anything in the real world is essentially zero luckily, but it's good to have it fixed."
https://github.com/floodyberry/poly1305-donna/issues/2#issuecomment-202698577
Commit in TweetNaCl.js: https://github.com/dchest/tweetnacl-js/commit/6dcbcaf5f5cbfd313f2dcfe763db35c828c8ff5b Commit in Poly1305-donna: https://github.com/floodyberry/poly1305-donna/commit/0911057b9607f37e642337739a2834aec84fbb53
Fixed a bug in the fast version of Poly1305 and brought it back.
Thanks to @floodyberry for promptly responding and fixing the original C code:
"The issue was not properly detecting if st->h was >= 2^130 - 5, coupled with [testing mistake] not catching the failure. The chance of the bug affecting anything in the real world is essentially zero luckily, but it's good to have it fixed."
https://github.com/floodyberry/poly1305-donna/issues/2#issuecomment-202698577
This update switches Poly1305 fast version back to original (slow) version.
This update switches Poly1305 fast version back to original (slow) version.
There was a bug in fast version of Poly1305 which sometimes produced incorrect results. Authenticity of results of the following functions may be affected: secretbox, secretbox.open, box, box.open.
Fast version is default if you used npm package (e.g. require("tweetnacl")).
TweetNaCl.js comes in two favors: nacl.js, which is almost the exact port of TweetNaCl, and nacl-fast.js, which includes faster versions ported from other implementations. The fast version of Poly1305 message authenticator comes from 16-bit version of floodyberry/poly1305-donna. The bug is present in this version and was ported to JavaScript.
Until we figure how to fix the bug, Poly1305 in nacl-fast.js was switched to original nacl.js.
Switched Poly1305 fast version back to original (slow) version due to a bug.
No code changes, just tweaked packaging and added COPYING.txt.
No code changes, just tweaked packaging and added COPYING.txt.
Breaking change! All functions from nacl.util have been removed. These functions are no longer available:
Breaking change! All functions from nacl.util have been removed. These
functions are no longer available:
nacl.util.decodeUTF8
nacl.util.encodeUTF8
nacl.util.decodeBase64
nacl.util.encodeBase64
If want to continue using them, you can include https://github.com/dchest/tweetnacl-util-js package:
<script src="nacl.min.js"></script>
<script src="nacl-util.min.js"></script>
or
var nacl = require('tweetnacl');
nacl.util = require('tweetnacl-util');
However it is recommended to use better packages that have wider
compatibility and better performance. Functions from nacl.util were never
intended to be robust solution for string conversion and were included for
convenience: cryptography library is not the right place for them.
Currently calling these functions will throw error pointing to
tweetnacl-util-js (in the next version this error message will be removed).
Improved detection of available random number generators, making it possible
to use nacl.randomBytes and related functions in Web Workers without
changes.
Changes to testing (see README).
Reverted license field in package.json to "Public domain".
No code changes.
Fixed undefined variable bug in fast version of Poly1305. No worries, this bug was _never_ triggered.
Exclude crypto and buffer modules from browserify builds.
crypto and buffer modules from browserify builds.Made nacl-fast the default version in NPM package. Now require("tweetnacl") will use fast version; to get the original version, use require("tweetnacl
nacl-fast the default version in NPM package. Now require("tweetnacl") will use fast version; to get the original version, use require("tweetnacl/nacl.js").Improved performance of curve operations, making nacl.scalarMult, nacl.box, nacl.sign and related functions up to 3x faster in nacl-fast version.
nacl.scalarMult, nacl.box,
nacl.sign and related functions up to 3x faster in nacl-fast version.Significantly improved performance of Salsa20 (~1.5x faster) and Poly1305 (~3.5x faster) in nacl-fast version.
nacl-fast version.Instead of using the given secret key directly, TweetNaCl.js now copies it to a new array in nacl.box.keyPair.fromSecretKey and nacl.sign.keyPair.from
nacl.box.keyPair.fromSecretKey and
nacl.sign.keyPair.fromSecretKey.Added new constant: nacl.sign.seedLength.
nacl.sign.seedLength.Even faster hash for both short and long inputs (in nacl-fast).
nacl-fast).Implement nacl.sign.keyPair.fromSeed to enable creation of sign key pairs deterministically from a 32-byte seed. (It behaves like libsodium's crypto_s
nacl.sign.keyPair.fromSeed to enable creation of sign key pairs deterministically from a 32-byte seed. (It behaves like libsodium's crypto_sign_seed_keypair: the seed becomes a secret part of the secret key.)Exported undocumented nacl.lowlevel.crypto_core_hsalsa20.
nacl.lowlevel.crypto_core_hsalsa20.Signature API breaking change! nacl.sign and nacl.sign.open now deal with signed messages, and new nacl.sign.detached and nacl.sign.detached.verify ar…
Signature API breaking change! nacl.sign and nacl.sign.open now deal
with signed messages, and new nacl.sign.detached and
nacl.sign.detached.verify are available.
Previously, nacl.sign returned a signature, and nacl.sign.open accepted a
message and "detached" signature. This was unlike NaCl's API, which dealt with
signed messages (concatenation of signature and message).
The new API is:
nacl.sign(message, secretKey) -> signedMessage
nacl.sign.open(signedMessage, publicKey) -> message | null
Since detached signatures are common, two new API functions were introduced:
nacl.sign.detached(message, secretKey) -> signature
nacl.sign.detached.verify(message, signature, publicKey) -> true | false
(Note that it's verify, not open, and it returns a boolean value, unlike
open, which returns an "unsigned" message.)
NPM package now comes without test directory to keep it small.
Fast version: increased theoretical message size limit from 2^32-1 to 2^52 bytes in Poly1305 (and thus, secretbox and box). However this has no impact
Note: The library is stable and API is frozen, however it has not been independently reviewed.
Note: The library is stable and API is frozen, however it has not been independently reviewed.
Your coding agent can read these notes before it upgrades. Set up the MCP server →