3 ms·
If, I assume the data is being sent back to their servers over HTTPS .. wouldn't that make this process of encrypting the "data" superfluous and have no impact
by xd 4y ago
If, I assume the data is being sent back to their servers over HTTPS .. wouldn't that make this process of encrypting the "data" superfluous and have no impact on the overall security - or did I miss something?
I'm not defending this mess just curious.
- CiPHPerCoder 4y agoThe vulnerability here is that their application-layer cryptography is vulnerable to adaptive chosen-ciphertext attacks, not that a passive observer could sniff packets and see plaintext.