• lazynooblet@lazysoci.al
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    9
    ·
    edit-2
    1 day ago

    The entire article seems like an attack. The author finds a unique identifier and adds “Russia bad” throughout.

    States the information is in cleartext but then explains how everything is encrypted (in transit).

    What will the author do if they intercepted any single online stores transfer of credit card details. Also encrypted in transit but Is that also deemed as cleartext? Or is that okay?

    I don’t think much new is learnt here. WhatsApp also sends metadata in “cleartext” (not really, as it’s encrypted in transit, but this article called that “cleartext”).

    • needanke@feddit.org
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      17 minutes ago

      States the information is in cleartext but then explains how everything is encrypted (in transit).

      That’s not how I understood it. The message context is allways encrypted in transit (using a novel encryption scheme). The auth_key_id however is not encrypted. And that can be used to track users as it is s(semi-)static.

    • irotsoma@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      1
      ·
      2 hours ago

      That’s not what I understood from the post, but could you point to the specifics of what you’re talking about in regards to the identifier being encrypted in transit? It seems the ID is sometimes obfuscated, but that is trivial to remove and not meant for security as mentioned.

    • T (they/she)@beehaw.org
      link
      fedilink
      arrow-up
      5
      arrow-down
      7
      ·
      1 day ago

      I don’t know… I think the author put a lot of effort on document things and presenting evidence.

      Your post history and mod logs are also quite weird.