GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    rysiek@mastodon.technology's status on Thursday, 13-Oct-2022 18:54:09 JSTrysiekrysiek

    Looks like #Telegram leaks usernames in #TLS SNI:
    https://nitter.it/fo0_/status/1580146963579740160

    ?♀️

    TLS SNI is sent in *clear text*, because it is a mechanism that informs the server hosting multiple websites on a single IP address which TLS certificate to present to the client.

    Putting username in SNI makes it *trivial* for anyone listening on the wire to track who and when is communicating with Telegram servers. Add some timing analysis and one can reason about who is talking to whom.

    Metadata kills.

    #Infosec

    In conversationThursday, 13-Oct-2022 18:54:09 JST from mastodon.technologypermalink

    Attachments

    1. No result found on File_thumbnail lookup.
      https://twitter.com/fo0_/status/1580146963579740160
      from fo0
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.