this post was submitted on 22 Oct 2024
66 points (100.0% liked)

Cybersecurity

5683 readers
6 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS
 

A recent investigation by the University of Toronto's Citizen Lab has uncovered potential security weaknesses in WeChat's custom encryption protocol. These weaknesses arise because the developers of WeChat, which boasts over a billion monthly active users, have modified the Transport Layer Security (TLS) 1.3 protocol, creating a version called MMTLS.

top 6 comments
sorted by: hot top controversial new old
[–] sylver_dragon@lemmy.world 29 points 3 weeks ago (1 children)

WeChat's software has security issues? Color me shocked. Shocked, I tell you.
Well, not that shocked.

Also:

WeChat's custom encryption protocol

Don't do that

[–] stoy@lemmy.zip 8 points 3 weeks ago

I thought we all agreed that WeChat is a security vulnerabilliy

[–] August27th@lemmy.ca 18 points 3 weeks ago

the developers of WeChat [...] have modified the Transport Layer Security (TLS) 1.3 protocol, creating a version called MMTLS.

Man in the Middle TLS

[–] praise_idleness@sh.itjust.works 6 points 3 weeks ago* (last edited 5 days ago)

nothing to see here :)

[–] AnUnusualRelic@lemmy.world 3 points 3 weeks ago

Next you're going to tell me that ROT13 is a problem?

[–] mindbleach@sh.itjust.works 2 points 3 weeks ago

Don't roll your own crypto.