Session Messenger prepares to weaken file encryption
discuss.privacyguides.net·21h
Flag this post

Hello, gravel here;

An upcoming change[1] to Session Messenger may undermine the encryption used for file attachments. The new encryption scheme is deterministic, meaning “the same user uploading an identical attachment results in an identical encrypted copy.”

I’d like to shed some light on this change, why I think it’s a problem, and suggest changes that preserve the qualities of deterministic encryption.

Disclaimer: I am not a cryptographer.

Before you proceed: if you’re aching to respond with “Session is trash anyway”, then this thread is not for you. Otherwise, feel free to continue reading.

To illustrate the issue with deterministic attachment encryption, imagine the following scenario…

Similar Posts

Loading similar posts...