Do It by Code
54 subscribers
710 photos
99 videos
14 files
1.24K links
We uhhhhh... do things by coding them.
Download Telegram
The most backdoor-looking bug I've ever seen (2021)
Article
Do It by Code
The most backdoor-looking bug I've ever seen (2021) Article
The article discusses a bizarre cryptographic bug that was discovered and fixed in the Telegram messaging app's protocol (called MTProto) around 7 years ago. The bug allowed Telegram's servers to perform an undetectable man-in-the-middle attack and decrypt all messages in supposedly end-to-end encrypted "secret chats".
The issue stemmed from Telegram using standard finite-field Diffie-Hellman key exchange to establish a shared secret between chat participants, but then pointlessly XORing the result with a server-provided nonce value. This allowed the server to manipulate the nonce so that both parties ended up with the same key, which the server also knew, breaking the encryption.

Removing the nonce step fixed the vulnerability, showing it served no legitimate purpose. The author finds this the most backdoor-looking bug they've seen, as the protocol designers seemingly went out of their way to add complexity that only enabled interception. An official Telegram statement apparently claimed the nonce was to protect clients with weak randomness, but the author dismisses this explanation as nonsensical.
While this is an old issue and there may be better reasons not to use Telegram today, the author still considers it a prime example of how blatant and bizarre cryptographic backdoors can look in practice. The unnecessary complexity is a big red flag.
Do It by Code pinned «https://copy.sh/v86»
https://go.dev/blog/chacha8rand

Explore the recent advancements in randomness within the Go programming language. Authors Russ Cox and Filippo Valsorda, part of the Go team, look closely at the complexities of addressing security requirements for specific use cases and the implementation of the ChaCha(Rand8) algorithm. Discover how these improvements have enhanced random number generation in Go, culminating in the seamless security enhancements introduced in Go 1.22.
Oops, ChatGPT has learned to create beautiful charts based on your data. 📊

Just upload a data file and ask, "create it in the form of bar graphs..."

Source
#GPT
Please open Telegram to view this post
VIEW IN TELEGRAM
Do It by Code via @wiki
https://en.wikipedia.org/wiki/Replay_attack
یکی از رایج ترین حمله های امنیتی
توی همه جا به کار میره، توی این ویکی پدیا یه مثال از authorization زده بود

ولی مثلا شما یه بازی رو در نظر بگیرین
داخل بازی، شما روی یه دکمه ای کلیک میکنین و یه پکت (packet) به سرور فرستاده میشه.
حالا من میخوام توی این بازی تقلب کنم و این کار رو خودکار سازی کنم (مثلا یه کد بنویسم که هر ۱۰ دقیقه یبار، اینو بفرسته به بک اند و ۲۴ ساعته هم رانش میکنم)
چیکار میکنم؟ میام میبینم بازی چه دیتایی رو داره به بک اند میفرسته، اینو ذخیره میکنم و بعدا دوباره میفرستمش =)

برای همین بک اند همیشه باید یه مکانیزمی برای جلوگیری از این حمله داشته باشه
1
Interact with your SQL database, Natural Language to SQL using LLMs
https://github.com/Dataherald/dataherald

AI Generation Studio (supports image to video)
https://klingai.com/
🔥1
You have no idea how much I hate you.
😁1
Forwarded from OpenUni
OpenUni
Photo
effective presentations