
Threema with Kenny Paterson, Matteo Scarlata and Kien Tuong Truong
Security Cryptography Whatever
00:00
Authentication of a Diffie-Hellman Ephemeral Key
It's actually an encryption of a Diffie-Hellman ephemeral value, plus some other fields. But it turns out that it's replayable, essentially. If you can get hold of the secret part of the key then you now know everything required to complete the handshake. The application keeps reusing it for seven days straight if you do not restart the application. And in fact, that is interestingly the case always with the application.
Transcript
Play full episode