3 ms·
Put simply: this attack required the user to enter the password 512 times[0] [0] https://mega-awry.io/#questions https://mega-awry.io/#questions
by herendin 4y ago
Put simply: this attack required the user to enter the password 512 times[0]
[0] https://mega-awry.io/#questions https://mega-awry.io/#questions
- tptacek 4y agoPut simply: this attack required the user to log in 512 times, ever. You don't have to take my word for it; that's how Mega summarizes the attack in their response.
- herendin 4y agoThe point is this exploit, according to the researchers, required massive and unusual manual intervention by the user, so it's very different from the other exploit you mentioned that involves millions of auth attempts From the link I just posted, written by the researchers: 'Nevertheless, on the clients that we analyzed, all attacks would have required a substantial number of manual login attempts (i.e., the user entering the password). Since clients usually cache the credentials, users often stay logged in, minimizing the number of logins performed and thereby increasing the difficulty of the attacks.'
- appleflaxen 4y agoThat's his/her point, right? > I have a Mega account and I think I've logged > in less than 50 times in the entire lifetime of my account... I also have a Mega account, and my experience is the same. You know a million times more about cryptography than me, but it doesn't change the fact that I, personally, am not compromised by an attack that requires me to log in that many times.
- bawolff 4y agoThat's not very many if "remember me" feature is broken and you use the service a lot. I suspect that there are non-malicious services i use where i have entered my password 500 times. Even if its a lot given average user behaviour, that's an incredibly low margin for safety
- lultimouomo 4y agoIf you have a personal and a school/work around on Microsoft platforms, and you use them daily, I bet you can be asked to log in 500 times in a couple of week of intense use. And each time you'll be asked if you want them to "remember you"!
- tptacek 4y agoSure, but I mean, this whole line of discussion is sort of brain-breaking. When we reason about cryptosystems, we don't generally reach the question of "how many hundreds of times can you log in before the system permanently loses all of its security". That's not like, a figure of merit in a typical cryptosystem; the right (and ordinary) answer to that question is "practically infinite". You've picked a sort of strange hill to die on when you find yourself arguing that a system is in practical terms secure because it's unlikely you're going to log in enough times to trip the bug that coughs up your private keys. If you have to compute the number of times you can safely log in, something has gone terribly, terribly wrong.
- lultimouomo 4y agoI completely argree, I was just using the chance to vent about how much I hate Microsoft logins.