Close Menu
Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Subscribe
    • Home
    • Top News
    • World
    • Economy
    • Science
    • Tech
    • Sport
    • Entertainment
    • Contact Form
    Aviation Analysis – Industry Travel NewsAviation Analysis – Industry Travel News
    Home»Tech»Sharehoster Mega: Security researchers actually decrypt protected data
    Tech

    Sharehoster Mega: Security researchers actually decrypt protected data

    Theodore MeeksBy Theodore MeeksJune 22, 2022No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email
    Sharehoster Mega: Security researchers actually decrypt protected data
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Security researchers at ETH (Swiss Federal Institute of Technology) in Zurich have uncovered errors in the end-to-end encryption of the Mega sharing host. By exploiting vulnerabilities, an operator or attacker can, under certain circumstances, view encrypted files.

    In fact, end-to-end encryption between the parties should ensure that only the rightful owner can decrypt their files. The operator cannot read plaintext across its infrastructure and attackers are also blocked – if the necessary encryption processes are implemented correctly.

    The problem has been resolved. But only temporarily?

    On a website, security researchers stated that this is not the case with Mega. The error was found in the implementation of problematic encryption. In a statement, Mega stated that it was able to at least partially solve the problem. More spots to follow. So far, no such attacks have occurred.

    Security researchers, for example, assert that the private key can no longer be accessed using their method. However, in their opinion, the implementation is still not optimal, and the additional attacks that they have identified could occur via other methods.

    the problems

    The massive client derives the keys for authentication and encryption from the user’s password. Among other things, the encryption key encrypts other keys, for example for chat functionality and file access. To ensure access from multiple devices, the private key is encrypted on massive servers.

    Since the keys do not have safety protection, the security researchers said that they intervened fraudulently. This enabled them to draw conclusions about prime numbers in the context of exchanging data for the session identifier. After 512 login attempts with the password, they were able to rebuild the private key bit by bit using an RSA key recovery attack.

    In order to be able to do this, you must provide access to the massive server infrastructure. The operator could theoretically decrypt the files or attackers in man-in-the-middle mode.

    More attacks

    Thus the operator or attacker can access the information in plain text. It is also conceivable that attackers can tamper with files stored by users or even send files infected with malicious code to victims who pass reliability checks. In their detailed report, the security researchers explained other attacks and identified potential attack scenarios.


    (From)

    to the home page

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Theodore Meeks

    Lifelong foodaholic. Professional twitter expert. Organizer. Award-winning internet geek. Coffee advocate.

    Related Posts

    Neodymium Magnet Uses and Safety Tips for 2025

    October 4, 2025

    Halifax Stanfield Airport Pilots Passenger Service Robots in Bid to Boost Traveler Experience

    August 25, 2025

    Battery miracle in test – HP Omnibook X AI: If it takes longer again

    August 29, 2024
    Navigate
    • Home
    • Top News
    • World
    • Economy
    • Science
    • Tech
    • Sport
    • Entertainment
    • Contact Form
    Pages
    • About Us
    • DMCA
    • Contact Form
    • Privacy Policy
    • Editorial Policy
    STAY UPTODATE

    Get the Latest News With Aviationanalysis.net

    OFFICE

    X. Herald Inc.
    114 5th Ave New York,
    NY 10011, United States

    QUERIES?

    Do you have any queries? Feel free to contact us via our Contact Form

    Visit Our Office

    X. Herald Inc.
    114 5th Ave New York,
    NY 10011, United States

    • About Us
    • DMCA
    • Contact Form
    • Privacy Policy
    • Editorial Policy
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.