HNHacker News
TopNewBestAskShowJobs

SP2njsPl2WmlAwM

42 karma · joined August 4, 2021

submissionscomments
SP2njsPl2WmlAwM··on An anonymous hacker reverse engineered my E2EE
> FWIW, I was expecting something like "the mechanism is fundamentally flawed because the e2e encryption actually is designed in a way where the server can derive or find the key"

The mechanism wasn't intentionally designed that way. But the symmetric ChatKeys were created with Random(), seeded (at least partially) with time().

SP2njsPl2WmlAwM··on Pitfalls of rolling your own E2EE protocol
Thanks a lot, that's quite valuable!

I was hoping to introduce both new and old readers with the "Context" section, but it seems I failed at that. The new post contains all of the content of the previous one and extends it a bit, which is why I didn't link the old one.

I removed the "Context" section now and replaced it with two short sentences addressed at readers of the previous post. I hope this makes it easier for new readers.

SP2njsPl2WmlAwM··on Pitfalls of rolling your own E2EE protocol
Thank you! Fixed.
SP2njsPl2WmlAwM··on My small revenge on Apple
To be clear: This is not meant as a direct attack, just to highlight some of the pitfalls of creating your own e2ee chat protocol.

I had a quick look at your app's e2ee and summarized my findings here: https://telegra.ph/Reviewing-the-app-behind-My-small-revenge...

Feel free to correct.