2026-02-18 02:14 UTC
@soatok Do you know if this is exploitable? I wasn't clear on whether you traced it that far.
Replies (1)
-
@mkj@social.mkj.earth 2026-02-18 12:52
@varx@cybersecurity.theater Setting your own key to all zeroes sure sounds exploitable by a participant to me (and in a group chat it would seem to make a third party actor's work given access only to ciphertext much easier); and truncating a HMAC sounds like something a malicious party along the network data path could do. So I would put both of those in the category of "plausibly exploitable" at least. @soatok@furry.engineer