Is Bob Sending Mixed Signals?

Is Bob Sending Mixed Signals?
复制标题

鲍勃发出了混合信号吗?

DOI:
10.1145/3139550.3139568
复制
发表时间:
2017
期刊:
Proceedings of the 2017 on Workshop on Privacy in the Electronic Society
影响因子:
--
通讯作者:
Nicholas Hopper
Nicholas Hopper
中科院分区:
--
文献类型:
--
作者:
Michael Schliep;Ian Kariniemi;Nicholas Hopper

文献摘要

被引文献

相似文献

对端到端安全消息传递的需求一直在快速增长,各公司已通过发布实现端到端安全消息传递协议的应用程序做出响应。Signal和基于Signal的协议在安全消息应用中占据主导地位。在这项工作中,我们分析了对话的安全属性提供的信号Android应用程序对各种真实的世界的对手。我们发现了一些漏洞,这些漏洞允许Signal服务器了解附件的内容,无法检测地重新排序和删除消息,以及从组对话中添加和删除参与者。然后,我们对应用程序执行概念验证攻击,以证明这些漏洞的实用性,并建议可以检测我们的攻击的缓解措施。我们的工作的主要结论是,我们需要考虑更多的机密性和完整性的消息时,设计未来的协议。我们还强调,协议必须防止受到损害的服务器,并至少实现信任但验证模型。
Demand for end-to-end secure messaging has been growing rapidly and companies have responded by releasing applications that implement end-to-end secure messaging protocols. Signal and protocols based on Signal dominate the secure messaging applications. In this work we analyze conversational security properties provided by the Signal Android application against a variety of real world adversaries. We identify vulnerabilities that allow the Signal server to learn the contents of attachments, undetectably re-order and drop messages, and add and drop participants from group conversations. We then perform proof-of-concept attacks against the application to demonstrate the practicality of these vulnerabilities, and suggest mitigations that can detect our attacks. The main conclusion of our work is that we need to consider more than confidentiality and integrity of messages when designing future protocols. We also stress that protocols must protect against compromised servers and at a minimum implement a trust but verify model.