github selfcustody/krux v26.09.0
Version 26.09.0

3 hours ago

Krux has a New Maintainer

Bom dia Kruxers!

My nym is Jean Do (jdlcdl on github and telegram). I have recently accepted the role of repository maintainer, taking over from Odudex for selfcustody krux. The primary reason for this release is simply for ME to make my first release, so that the community is informed. Little has changed since last month's krux-v26.08.0.

New Krux Disclaimer

Kruxers will immediately see a disclaimer that must be acknowledged after an upgrade. Upon acknowledgement, the current version string "26.09.0" will be persisted to a file named "/flash/disclaimer" so that the disclaimer is not repeated after every boot. You can always review the disclaimer in "About" -- where you'll also find a QR leading to the official Krux documentation.
Appropriate for this past summer, this version's disclaimer informs users of Krux's innovative "Research and Development" focus. Its intent is to ground user expectations, reinforce "Don't trust, verify.", and ensure users assume responsibility for their decision to use Krux.

SECURITY NOTICE

Please remember to look out for these warnings not only here, but also at other projects you rely on. The vulnerability described below, I deem, non-critical.

In the past month, a potential security-vulnerability was responsibly disclosed by an anonymous kruxer. The issue was a real buffer-overflow of 12 bytes which was occurring during encrypt and decrypt operations that used Krux default AES-GCM for KEF encryption. The 12 bytes that were overflowing came from a 16 byte GCM auth-tag returned to a caller who was only capturing 4 bytes (used by KEF GCM versions), thus a 12-byte overflow. These extra bytes should be meaningless outside the GCM auth-tag context, appearing random, but it remains unknown where exactly they were flowing into -- and which memory structure(s) they would have been corrupting. The caller's buffer (in MaixPy's ucryptolib module) was extended to 16 bytes to resolve the overflow and still returns a truncated 4 byte auth-tag so that APIs are unchanged.

There is NO CHANGE to existing KEF envelopes and NO ACTION NECESSARY to take for users. There have been no reports of exploits, and it is my belief that this flaw is NOT practically exploitable; I remain open to consider and discuss others' concerns.

New Features

  • The mnemonic recovery flow now prioritizes format selection (QR Code, Words, From Storage, Other Formats) at the start, simplifying common recovery paths and improving user experience.
  • Added units and allowed ranges to numeric editors for Screensaver Time, Shutdown Time, and Buttons Debounce, providing clearer input guidance.

Bug Fixes and Hardening

  • Corrected the GCM tag buffer size to match the 16 bytes written by the SDK, ensuring proper handling of cryptographic tags and maintaining compatibility with existing KEF envelopes.
  • Fixed issues where pressing 'back' incorrectly triggered "failed to load" errors in the SD card file browser and QR scanner. Error handling is now more robust, distinguishing between user cancellation and actual load failures.
  • Updated Embit to v0.8.2, incorporating hardened PSBT checks.
  • Past verification of ktool firmware-flasher binaries since v23.09.0; inclusion of these utilities in standard binary-reproducibility checks.

Improvements

  • Added a critical privacy warning to the tamper detection documentation, alerting users that camera frames are stored unscrambled and could potentially be reconstructed from a flash dump.
  • Clarified the entropy measurement label display as "Estimated entropy:".

Documentation

  • Updated the security contact information to include Jean Do.
  • Fixed dependency freezing issues related to uv auto-updating libraries.
  • Updated mkdocs.yml variables and contributor keys, and emphasized the importance of verifying both authenticity and integrity checks.

Thank you contributors!

I would like to thank all of the Krux contributors who have applied their ideas, hard-work, precious time, code and critical-eyes towards the changes in this release, including: @odudex, @joaozinhom, @Naman015, @qlrd, @notTanveer, @tadeubas, @kkdao, as well as all who contribute in the telegram communities.

Onward

The Krux community has much to look forward-to in the coming year. Contributors are exploring new hardware, use of NFC for encrypted secrets, silent payments, better message signing and descriptor backups, use of PSBTv2, UI/UX improvements and also under-the-hood refactorings to ease maintenance. While there is much to be excited for, since Krux is running on discontinued K210 hardware, we will need contributions from the community to expand to more microcontroller boards. Please consider contributing any way that you can. I look forward to making progress with you in the github issues and PRs -- and on telegram.


Assets included below were signed by me using my own GPG key and the selfcustody firmware signing key.
See ATTESTATION.txt for details.

Don't miss a new krux release

NewReleases is sending notifications on new releases.