4 ms·
It appears the attack is based on a failed login leaking information, and that 512 failed logins would be enough for Mega itself to crack the key. But, to be a
by herendin 4y ago
It appears the attack is based on a failed login leaking information, and that 512 failed logins would be enough for Mega itself to crack the key.
But, to be a practical attack, the client software would first have to be modified to conceal the suspiciously big number of bogus failed logins from the end user (if I understood clearly)
- NAR8789 4y agoThis is sloppy summarizing by ars. In a real attack tampered logins need not show up as failures. From the original article https://mega-awry.io/ https://mega-awry.io/ (emphasis mine): > Since the server code is not published, we cannot implement a Proof-of-Concept (PoC) in which the adversary actually controls MEGA. Instead, we implemented a MitM attack by installing a bogus TLS root certificate on the victim. > ... > The log in attempt fails, which is only a limitation of the MitM setting. A malicious cloud provider can perform this attack without the user noticing.
- herendin 4y ago>tampered logins need not show up as failures. Thanks for clarifying it. Yes, the writing about it is surprisingly unclear. Even on the original paper and the dedicated website for this bug, there's a frustrating lack of clarity about what they mean by "login" and how much the user is in the loop of this attack, which could be an important gating factor making it unlikely to ever have been a practical exploit