To conceal them might be possible in some cases, but requires tampering suspiciously with public source client-side apps
To conceal them might be possible in some cases, but requires tampering suspiciously with public source client-side apps
This isn't a cryptosystem, it's a CTF level.
You don't have to take my word for it; that's how Mega summarizes the attack in their response.
From the link I just posted, written by the researchers:
'Nevertheless, on the clients that we analyzed, all attacks would have required a substantial number of manual login attempts (i.e., the user entering the password). Since clients usually cache the credentials, users often stay logged in, minimizing the number of logins performed and thereby increasing the difficulty of the attacks.'
> I have a Mega account and I think I've logged
> in less than 50 times in the entire lifetime of my account...
I also have a Mega account, and my experience is the same.You know a million times more about cryptography than me, but it doesn't change the fact that I, personally, am not compromised by an attack that requires me to log in that many times.
Even if its a lot given average user behaviour, that's an incredibly low margin for safety
You've picked a sort of strange hill to die on when you find yourself arguing that a system is in practical terms secure because it's unlikely you're going to log in enough times to trip the bug that coughs up your private keys. If you have to compute the number of times you can safely log in, something has gone terribly, terribly wrong.