GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 19-Feb-2026 11:04:25 JST Soatok Dreamseeker Soatok Dreamseeker

    RE: https://furry.engineer/@soatok/116088639302283341

    So, Matrix responded with a blog post.

    I added an addendum to mine to rebut theirs: https://soatok.blog/2026/02/17/cryptographic-issues-in-matrixs-rust-library-vodozemac/#matrix-response

    In conversation about 7 months ago from furry.engineer permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Soatok Dreamseeker (@soatok@furry.engineer)
      from Soatok Dreamseeker
      https://soatok.blog/2026/02/17/cryptographic-issues-in-matrixs-rust-library-vodozemac/ #Matrix #infosec #vulnerabiltiy #cryptography #privacy
    2. Domain not in remote thumbnail source whitelist: soatok.blog
      Cryptographic Issues in Matrix’s Rust Library Vodozemac
      from Soatok
      Two years ago, I glanced at Matrix’s Olm library and immediately found several side-channel vulnerabilities. After dragging their feet for 90 days, they ended up not bothering to fix any of i…
    • Embed this notice
      Garbage Data 🦝 (anomalocarididae@furry.engineer)'s status on Thursday, 19-Feb-2026 11:11:41 JST Garbage Data 🦝 Garbage Data 🦝
      in reply to

      @vavsvirtual hey you you wanted to read this article right? well now there's more

      In conversation about 7 months ago permalink
    • Embed this notice
      LogicalErzor (logical_error@fosstodon.org)'s status on Saturday, 21-Feb-2026 00:21:21 JST LogicalErzor LogicalErzor
      in reply to

      @soatok im still a little confused how the identity element is a problem

      let’s say i have a group chat with friends:
      - one friend uses a client that sets identity element to 0 (whether purposefully setting it or downloading a malicious client unaware it’s disguised as an encrypted client)
      - anyone sniffing the traffic between us can trivially decrypt the messages?

      do i have that right?

      In conversation about 7 months ago permalink
    • Embed this notice
      Soatok Dreamseeker (soatok@furry.engineer)'s status on Saturday, 21-Feb-2026 00:21:21 JST Soatok Dreamseeker Soatok Dreamseeker
      in reply to
      • LogicalErzor

      @Logical_Error Yes, assuming they can observe the ciphertext.

      If Matrix is deployed with well-configured TLS, this means probably only the homeserver is in a position to do this. If Matrix isn't, it's free real estate for QUANTUMINSERT and other attacks.

      You and your friends will be "using" encryption, believing that your messages are private, while not having any real confidentiality.

      This is a cryptographic protocol failure that results in silently losing confidentiality without warning. In the context of cryptographic attacks, the severity is pretty high.

      Could the users also just give their private key to an adversary? Yes, but that requires an out-of-band signal. This compromises privacy without any external leak.

      In conversation about 7 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.