Skip to content

Remove insecure Math.random() fallback - #70

Open
alexgleason wants to merge 1 commit into
LinusU:masterfrom
alexgleason:remove-insecure-fallback
Open

Remove insecure Math.random() fallback#70
alexgleason wants to merge 1 commit into
LinusU:masterfrom
alexgleason:remove-insecure-fallback

Conversation

@alexgleason

Copy link
Copy Markdown

Why

The Math.random() fallback existed because the old "Debug JS Remotely" mode ran the JS bundle in desktop Chrome's V8, where synchronous native module calls are impossible (nativeCallSyncHook is undefined), so calling getRandomBase64 would throw. The fallback kept apps from crashing while debugging — at the cost of crypto.getRandomValues silently returning predictable values.

That rationale no longer applies:

  • Remote debugging in Chrome was removed from React Native before 0.81, the minimum version this package now supports.
  • On the new architecture, the existing RN$Bridgeless check already made the fallback dead code.

What

Removes insecureRandomValues, isRemoteDebuggingInChrome, and the branch that invoked them. getRandomValues now always uses a real CSPRNG (ExpoCrypto if present, otherwise the native module). If the native module were ever unavailable, TurboModuleRegistry.getEnforcing throws instead of silently degrading — the right failure mode for a polyfill that applications use to generate key material (e.g. wallet private keys), where a silently weak RNG is a catastrophic failure. This class of bug has caused real-world thefts (e.g. the BitcoinJS "Randstorm" disclosures).

The fallback existed because remote debugging in Chrome ran the JS
bundle in the browser's V8, where synchronous native module calls are
not supported. Remote debugging in Chrome was removed from React Native
before 0.81, the minimum version this package supports, and the
bridgeless check already made this path dead code on the new
architecture.

Removing it guarantees that crypto.getRandomValues can never silently
return predictable values from Math.random(), which is the correct
failure mode for code generating key material. If the native module is
unavailable, TurboModuleRegistry.getEnforcing throws instead.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant