3 ms·
"If there was a way to efficiently cycle through DH parameters, an active man-in-the-middle attacker could spoof the fingerprint." Isn't this a rather big if?
by andyrj 12y ago
"If there was a way to efficiently cycle through DH parameters, an active man-in-the-middle attacker could spoof the fingerprint."
Isn't this a rather big if? In my limited understanding of the math involved, the whole reason dhe is still secure is because this isn't the case. Which means an attacker couldn't just use any old sha1 collision, it would have to corellate to a valid set of dh params, which would have an effect on the computational complexity, right?
- yk 12y agoThis is not a attack on DH, it is a attack on the verification mechanism. So the trick is, the attacker does not need to break DH, he just needs to find two sufficiently similar DH parameters, that the verification still works.
- andyrj 12y agoI understand that this is not an attack on DH. I have not analyzed telegram but the statement I quoted seems to indicate it would need to be able to quickly generate many DH params. That doesn't seem to be a a computationally trivial task. http://security.stackexchange.com/questions/51129/can-you-generate-diffie-hellman-parameters-quickly http://security.stackexchange.com/questions/51129/can-you-ge... It seems like for this attack to be realistic you would need the math underlying DH to be broken somehow. At which point I think there are many applicatons who's security would be compromised that are far more disturbing than the security of telegram. Again I am asking for clarification because I may be misunderstanding the use of the quoted text and I have not looked at the code myself. As I read it, this analsis seems akin to someone stating that, a wall provides no security if we lived in an alternative universe where solids could freely pass through one another. That statement maybe true but who cares, that universe wouldn't continue using walls for security measures anyways. Excuse my metaphor there, I hope it clears up what I was asking about.
- yk 12y agoAs far as I understand the attack, the attacker brute forces his own DH secret, not the DH parameters. So attacker has the parameters for both connections, gets the public keys from both chat partners and then brute forces two secrets such that the hashes of the resulting DH shared secret match. For this the attacker needs 'only' to brute force the keys, not the parameters.