Elektrine lite

← Feed

@kimapr@ublog.kimapr.net

Post #2443477

2026-02-18 09:20 UTC

Like idk maybe i’m missing something, but there seem to be two scenarios where this could be exploited: a malicious server that can already swap out encryption keys without being noticed (say a big group chat where no one ever does the emoji verification thing) could swap in this sussy identity key. but why? they can just use a normal fake key. bonus points for being less noticeable!a malicious participant of the room, who is already trusted by all other members to read messages in the room and not leak them, decides to betray the group in an unnecessarily convoluted and easily detectable way, by breaking encryption in the chat and making it readable to the server (if they bother to check for this anyway). but why? besides just not betraying trust of people you talk with, there are easier ways to accomplish this, for example telnetting into the NSA to dump all the messages in plaintext (bonus points for making them visible to the ISP too) Two people asked for clarification on what the actual practical impact of the vuln is, and Soatok just ignored them while responding to other comments.. maybe because it’s not as impactful as he makes it out to be and he doesn’t wanna admit that 🙄

Replies (0)

No replies.