3 ms·
> You make an encrypted file. After that the only way to decrypt it is the way it was encrypted. Check out the linked S3 SDK vulnerability, it's precisely abou
by FiloSottile 6y ago
> You make an encrypted file. After that the only way to decrypt it is the way it was encrypted.
Check out the linked S3 SDK vulnerability, it's precisely about decrypting a file in a different way from how it was encrypted :)
- upofadown 6y agoLooks like an oracle attack against malleable encryption. It does something clever to enhance the effectiveness of that attack but nothing there could reasonably be considered negotiation.
- FiloSottile 6y ago> Title: In-band key negotiation issue in AWS S3 Crypto SDK for golang