feld,
@feld@bikeshed.party avatar

I found this last night after a ton of digging but I don't know if it's true. Strange that this isn't more widely publicized.

https://mtpsym.github.io/

mischievoustomato,
@mischievoustomato@rebased.taihou.website avatar

@feld can someone not into cryptography and shit read this?

feld,
@feld@bikeshed.party avatar

@mischievoustomato it's theoretical stuff like:

They may be able to affect the order of messages by spamming millions of crafted messages to your client

They may be able to intercept messages for a server (not decrypt, just get in the middle) by sending billions of crafted messages to the server

The crypto does too much work on data before validating it wasn't tampered with (checks the decrypted contents with a checksum, not the encrypted payload)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • mdbf
  • ethstaker
  • magazineikmin
  • cubers
  • rosin
  • thenastyranch
  • Youngstown
  • osvaldo12
  • slotface
  • khanakhh
  • kavyap
  • InstantRegret
  • Durango
  • JUstTest
  • everett
  • tacticalgear
  • modclub
  • anitta
  • cisconetworking
  • tester
  • ngwrru68w68
  • GTA5RPClips
  • normalnudes
  • megavids
  • Leos
  • provamag3
  • lostlight
  • All magazines