4 ms·
> FWIW, I was expecting something like "the mechanism is fundamentally flawed because the e2e encryption actually is designed in a way where the server can deri
by SP2njsPl2WmlAwM 5y ago
> FWIW, I was expecting something like "the mechanism is fundamentally flawed because the e2e encryption actually is designed in a way where the server can derive or find the key"
The mechanism wasn't intentionally designed that way. But the symmetric ChatKeys were created with Random(), seeded (at least partially) with time().
- entropic88 5y agoThis recently happened with a Bitcoin wallet app called Cake wallet. They used time() in their random number generator which allowed the key generation to be replicated and funds stolen.
- suifbwish 5y agoWhat’s wrong with just using /dev/urandom for the entropy pool?