Breaking the Threema Secure Messenger
breakingthe3ma.app
breakingthe3ma.app
this is bad
> we show that the attacker can trick a user into creating a valid vouch box and sending it to the attacker. This allows the attacker to impersonate the client to the server forever.
This attack means that, under some circumstances, a user might compromise his or her own account by simply sending a message to another user.
Yikes
The title of the paper presents a more academic angle, and is intended to highlight what the "learned lessons" are, but let's not forget that Threema was vulnerable to our attacks for 10+ years.