> end-to-end encrypted
O RLY?
https://git.jami.net/savoirfairelinux/ring-client-android/is...
https://security.stackexchange.com/a/171461/43688
I looked through their code to see where data is being encrypted/decrypted, and was unable to locate it.
Since their issue indicated they use 4096-bit RSA, I really wanted to see if they were vulnerable to Bleichenbacher's 1998 padding oracle attack.
https://git.jami.net/savoirfairelinux/ring-project/wikis/tec...
> The SHA-1 fingerprint (160-bits) of this public certificate is the JamiId.
this-is-fine.mp4