4 ms·
the blog post is well written and underlines the fact that Paterson and students tend to oversell the magnitude of the bugs they find and patch in messengers, a
by ethnut 4y ago
the blog post is well written and underlines the fact that Paterson and students tend to oversell the magnitude of the bugs they find and patch in messengers, always with quite the publicity involved and often overstating the rarity of the circumstances occurring that lead to the bugs
- tptacek 4y agoNo, they don't, and the "rarity of the circumstances" thing is irrelevant. These are academic cryptography researchers doing academic cryptography research, and this blog post engages with it as if it was a hostile Consumer Reports review. The point of this research isn't to make a decision about what messenger you use. The point is to help inform the designers of future, better messaging protocols about what does and doesn't work. Threema's design is littered with stuff that didn't work; it's an important cautionary tale. You can, according to the paper, send a classic Threema protocol user a message that, if repeated or forwarded, allows someone else to log in as them. That's a distinctively weird and bad problem for a protocol to have. As I said in a comment elsewhere: the Matrix vulnerabilities were much more damaging to Matrix, but the Threema vulnerabilities were much worse as cryptographic flaws. There is more to learn from Threema's failures than from Matrix's.
- ethnut 4y agoI agree with the need for the research in the area. they are a big team and the yearly bug they identify in messenger services benefit the public. I lament the dissemination by that group, always through a PR wave trying to place shocking headlines amplified by the school PR. that was the same in their past discoveries.
- shaldengeki 4y agoYou've accused the researchers twice now of exaggerating the importance of the vulnerabilities they found. This comment is almost entirely unresponsive to the comment you're replying to, which states: > You can, according to the paper, send a classic Threema protocol user a message that, if repeated or forwarded, allows someone else to log in as them. That's a distinctively weird and bad problem for a protocol to have. Can you be precise about what specific claims they made and how the claims were deceptive?
- UncleEntity 4y agoA highly motivated nation state actor can (sometimes) turn a rare circumstance into a reliable exploit. Or some other researcher with a different mindset. Image if they tried to downplay the heartbeat or speculative execution bugs with arguments like “but you’d need access to the server and what can you do with a small chunk of memory anyway?” IMHO just take your swat on the nose and fix your shit without going into defensive mode is the way to handle these things.
- hammerhead82 4y ago[flagged]