-
-
Notifications
You must be signed in to change notification settings - Fork 197
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Decrypt Interim Note-Changes file #570
Comments
ok.. i'm so far that I can extract the "notes" from the file. Checksum checks out, i've got an iv, but it needs a derived key from the master password called |
It seems that the logSessionKey is created from WallSessionKey, which is a key generated from the master password and a constant log session salt.. (sorry for the rubber ducking 🦆) I'm stuck at the "masterSalt"... It should be stored somewhere, but I'm not sure where. Edit: I found the masterSalt in the notes & settings file, which includes a plist at the start. Among other things, I've found hastIterationCount as well, which is a different number than the default one (8000) Edit: I'm trying to check if my computed master key matches the verification key... it doesn't and I'm not sure why not. |
I've got the computer masterkey matching the verification (yay!). The next step is to compute the key and iv for the aes-256-cbc decryption, which I think i did right (i got the nvalt to compile through AppCode and i can output the actual key and iv, which is the same ones that I generate). Unfortunately, i get an error during decryption (EVP_DecryptFinal fails), which could indicate a wrong key (which would result from a wrong passphrase).. I'm a bit stuck again.. but hopeful I can figure this out... Edit: I can decrypt my main notes&settings database with the help of the dataSessionSalt. It seems that everything is correct. The only thing that might be an issue, is the logSessionKey. This is taken from the sessionSalt, which is a constant salt "Salt for encrypting a write-ahead-log session\0" Edit: I finally decrypted the notes (it uses a constant logsessionkey), and could decompress my note. Strange thing is that i still find 244 notes (which is the same amount i have right now).. however, the |
After repartitioning a disk, it seems I've lost some notes. Not all of them, just from the last two months. Since the directory was gone, I had to change the Notes & Settings directory so it points again to the correct "Notational Data" directory. This restored everything but the last few months.
I think this is related to #339, which looks like the last data is written to
~/Library/Caches/net.elasticthreads.nv/Interim Note-Changes
file.This file is about 440Kb, while my regular "Notes & Settings" is only 320kb.
I've tried things like renaming the interim file, but nothing seems to work. I have the master password and looked around in WALController.m to see how things work, but my C# is pretty lousy to be honest. Is it possible to extract the data from this file?
The text was updated successfully, but these errors were encountered: