With that said, the details of this one look kind of exciting. Unfortunately the technical details are in Chinese and aren’t translating well for me.

Ok I found the TU Darmstadt paper that initially disclosed the flaws. TL;DR user hashing to implement a (bad) private set intersection protocol, and its trivially vulnerable to brute-force dictionary attacks.

Apple has known since 2019 and didn’t fix it! usenix.org/system/files/sec21-

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.