Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
martinralbrecht
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
martinralbrecht
8mo ago
Note that WhatsApp as a web client, too: https://eprint.iacr.org/2025/794
2.
▲
by
martinralbrecht
8mo ago
We did reverse engineer it and we're cryptographers not reverse engineering experts https://eprint.iacr.org/2025/794
3.
▲
by
martinralbrecht
8mo ago
WhatsApp's end-to-end encryption has been independently investigated: https://kclpure.kcl.ac.uk/ws/files/324396471/whatsapp.pdf Full version here: https://eprint.iacr.org/2025/794.pd
4.
▲
by
martinralbrecht
2y ago
Telegram's symmetric cryptography has been reviewed by cryptographers: https://mtpsym.github.io/
5.
▲
by
martinralbrecht
2y ago
We explain this under the heading "A Somewhat Opinionated Discussion" here: https://mtpsym.github.io/ which is our security analysis of MTProto's symmetric cryptography.
6.
▲
by
martinralbrecht
3y ago
NIST responded: https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W2VO ...
7.
▲
by
martinralbrecht
3y ago
NIST responded: https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W2VO...
8.
▲
Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]
(haddadi.github.io)
278 points
by
martinralbrecht
3y ago
|
153 comments
9.
▲
by
martinralbrecht
3y ago
"As independent information security and cryptography researchers, we build technologies that keep people safe online. It is in this capacity that we see the need to stress that the safety provided by these essential technologies is no
10.
▲
by
martinralbrecht
3y ago
- Issue 1: using uninitialised keys. - Issue 2: IV reuse in AES-GCM when a file is re-encrypted after an update. - Issue 3: a malicious server can place a chosen key in a victim user's encrypted keystore; the user then rotates everyt
11.
▲
“Breaking Cryptography in the Wild: Nextcloud”
(twitter.com)
4 points
by
martinralbrecht
3y ago
|
1 comments
12.
▲
by
martinralbrecht
4y ago
Cool, thanks! That's interesting to know. Do you know how they deal with FOI and auditable communications in this case? PS: I talked about the seemingly unexploitable IND-CCA vulnerability because it means Matrix can't give you so
13.
▲
by
martinralbrecht
4y ago
Since Matrix (and thus BundesMessenger?) currently doesn't provide standard security guarantees for its end-to-end encryption (the mitigation to the "Simple confidentiality break" from https://nebuchadnezzar-megolm
14.
▲
by
martinralbrecht
4y ago
re: implementation bugs: Almost, but not quite. See https://nebuchadnezzar-megolm.github.io/#anticipated-questio... Also note that in the review of the ecosystem the Matrix developers, i.e you :), also discovered further cl
15.
▲
by
martinralbrecht
4y ago
We explain how this works in Appendix A of https://nebuchadnezzar-megolm.github.io/static/paper.pdf but it's also a nice little exercise to work out how this breaks confidentiality. TL;DR: Yes, the plaintext comin
16.
▲
by
martinralbrecht
4y ago
A quick comment on this, we did address this in our paper: "In environments where cross-signing and verification are enabled, adding a new unverified user adds a warning to the room to indicate that unverified devices are present. Howe
17.
▲
by
martinralbrecht
4y ago
This isn't correct. Several of our attacks succeeded without any warnings popping up. Furthermore, you need to distinguish between what Element happened to do (which users may or may not watch out for) and what the standard demanded. N
18.
▲
by
martinralbrecht
4y ago
We had working exploits for those vulnerabilities where exploiting them wasn't immediately obvious. We shared those with the Matrix developers but didn't publish them because there was no dispute on whether our attacks were practi
19.
▲
by
martinralbrecht
4y ago
Indeed: > While the Matrix specification does not require a mitigation of this behaviour, when a user is added to a room, Element will display this as an event in the timeline. Thus, to users of Element this is detectable. However, such
20.
▲
by
martinralbrecht
4y ago
Unfortunately, it is not quite so simple: > Does this mean that Matrix does not provide confidentiality and/or authentication? > Matrix and its implementations can, after today’s fixes, provide confidentiality and authentication
21.
▲
by
martinralbrecht
4y ago
Several of these bugs were indeed on the protocol level: https://nebuchadnezzar-megolm.github.io/
22.
▲
by
martinralbrecht
4y ago
This is discussed by the research team who reported these issues (I'm one of those researchers) at: https://nebuchadnezzar-megolm.github.io/ > Are these attacks design flaws in the Matrix specification? > We will
23.
▲
by
martinralbrecht
4y ago
Writeup of these vulnerabilities and attacks by the research team who reported them: https://nebuchadnezzar-megolm.github.io/
24.
▲
by
martinralbrecht
4y ago
- Matrix announcement: https://matrix.org/blog/2022/09/28/upgrade-now-to-address-en... - Write-up by research team: https://nebuchadnezzar-megolm.github.io/
25.
▲
by
martinralbrecht
4y ago
Write-up of the vulnerabilities and attacks by research team who reported them: https://nebuchadnezzar-megolm.github.io/
26.
▲
Practically-Exploitable Cryptographic Vulnerabilities in Matrix
(nebuchadnezzar-megolm.github.io)
18 points
by
martinralbrecht
4y ago
|
1 comments
27.
▲
by
martinralbrecht
5y ago
> As an aside, Jakobsen and Orlandi wrote: “We stress that this is a theoretical attack on the definition of security and we do not see any way of turning the attack into a full plaintext-recovery attack.” Similarly, the Telegram “FAQ fo
28.
▲
by
martinralbrecht
5y ago
RC4: https://en.wikipedia.org/wiki/Wired_Equivalent_Privacy#Weak_...
29.
▲
by
martinralbrecht
5y ago
https://shattered.io/
30.
▲
by
martinralbrecht
5y ago
1. Re: "needs additional work to become a fully fledged exploit": We have verified this attack in practice, see the paper. 2. We give an example application where it has some "bearing on the security of messages" at the
More ›