Elektrine lite

← Feed

@varx@cybersecurity.theater

2026-02-18 02:14 UTC

@soatok Do you know if this is exploitable? I wasn't clear on whether you traced it that far.

Replies (1)

  • @mkj@social.mkj.earth 2026-02-18 12:52

    @varx@cybersecurity.theater Setting your own key to all zeroes sure sounds exploitable by a participant to me (and in a group chat it would seem to make a third party actor's work given access only to ciphertext much easier); and truncating a HMAC sounds like something a malicious party along the network data path could do. So I would put both of those in the category of "plausibly exploitable" at least. @soatok@furry.engineer

    Open ##2443484