this post was submitted on 22 Oct 2024
66 points (100.0% liked)

Cybersecurity

5928 readers
69 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
 

A recent investigation by the University of Toronto's Citizen Lab has uncovered potential security weaknesses in WeChat's custom encryption protocol. These weaknesses arise because the developers of WeChat, which boasts over a billion monthly active users, have modified the Transport Layer Security (TLS) 1.3 protocol, creating a version called MMTLS.

all 6 comments
sorted by: hot top controversial new old
[–] [email protected] 29 points 2 months ago (1 children)

WeChat's software has security issues? Color me shocked. Shocked, I tell you.
Well, not that shocked.

Also:

WeChat's custom encryption protocol

Don't do that

[–] [email protected] 8 points 2 months ago

I thought we all agreed that WeChat is a security vulnerabilliy

[–] [email protected] 18 points 2 months ago

the developers of WeChat [...] have modified the Transport Layer Security (TLS) 1.3 protocol, creating a version called MMTLS.

Man in the Middle TLS

[–] [email protected] 3 points 2 months ago

Next you're going to tell me that ROT13 is a problem?

[–] mindbleach 2 points 2 months ago

Don't roll your own crypto.