3 ms·
This attack started with a well known pattern where protocols where you can freely mutate cyphertext in transit usually end of building a decryption oracle into
by zmanian 10y ago
This attack started with a well known pattern where protocols where you can freely mutate cyphertext in transit usually end of building a decryption oracle into them that an attacker can exploit.
Then they found a novel oracle in the image decryption system.
Then big change at Apple lately is that on top of having world class cypto and security people they are publishing a lot more of their design work for peer review. This will lead to much more secure systems when they replace the iMessage crypto.
- hannob 10y agoIf Apple has world class crypto people then they had nothing to do with the design of imessage. It didn't take the attack from Green and Co to see that this crypto design is very strange and doesn't follow any kind of modern best practice. (And no, the fact that it's 5 years old doesn't make things better. "Use an AEAD" and "use PFS" are things that one could've known in 2011.)