EILMELDUNGEN LIVE
🔧 ProgrammierungGetting started with JAX on NVIDIA GPUs(26.08.2026 um 21:03 Uhr)
🔧 ProgrammierungScale JAX models to multi-GPU systems(26.08.2026 um 21:03 Uhr)
🔧 ProgrammierungHow to build and scale multi-agent AI systems on GKE(27.08.2026 um 00:42 Uhr)
🎥 PodcastsThis company has more AI agents than employees(24.08.2026 um 18:00 Uhr)
🎥 PodcastsThe AI skill everyone should have(24.08.2026 um 22:00 Uhr)
🎥 PodcastsTech, labor, and token costs: the new AI math(26.08.2026 um 22:00 Uhr)
🔧 AI Nachrichten local.ai: hardware benchmarking for local AI models(23.08.2026 um 17:00 Uhr)
🎥 PodcastsHow GitHub's tiny wins team fixes developer paper cuts(24.08.2026 um 17:00 Uhr)
🔧 ProgrammierungHow Holafly eSIM app with 2M MAU is powered by Flutter(25.08.2026 um 18:01 Uhr)
🕵️ SicherheitslückenMySQL Governance(26.08.2026 um 19:58 Uhr)
🔧 ProgrammierungGetting started with JAX on NVIDIA GPUs(26.08.2026 um 21:03 Uhr)
🔧 ProgrammierungScale JAX models to multi-GPU systems(26.08.2026 um 21:03 Uhr)
🔧 ProgrammierungHow to build and scale multi-agent AI systems on GKE(27.08.2026 um 00:42 Uhr)
🎥 PodcastsThis company has more AI agents than employees(24.08.2026 um 18:00 Uhr)
🎥 PodcastsThe AI skill everyone should have(24.08.2026 um 22:00 Uhr)
🎥 PodcastsTech, labor, and token costs: the new AI math(26.08.2026 um 22:00 Uhr)
🔧 AI Nachrichten local.ai: hardware benchmarking for local AI models(23.08.2026 um 17:00 Uhr)
🎥 PodcastsHow GitHub's tiny wins team fixes developer paper cuts(24.08.2026 um 17:00 Uhr)
🔧 ProgrammierungHow Holafly eSIM app with 2M MAU is powered by Flutter(25.08.2026 um 18:01 Uhr)
🕵️ SicherheitslückenMySQL Governance(26.08.2026 um 19:58 Uhr)

11 🕛 kürzlich 2 Min Lesezeit 10 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | Payload Compromised: Full Key Recovery in Rocket.Chat E2EE

↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
56 YouTube-Aufrufe
Rocket.Chat is used in more than 150 countries, where many organizations rely on its end-to-end encryption (E2EE) for security-critical communication. This talk presents the first comprehensive analysis of Rocket.Chat's E2EE as deployed in real systems. By combining automated symbolic analysis with in-depth manual inspection of the implementation, we identify practical attacks that break both confidentiality and integrity.

Our most severe finding is a practical key-recovery attack.
An attacker with access to encrypted user backups can recover private keys and all derived group keys in twelve days under realistic assumptions. We validate this attack with practical proof-of-concept exploits. This results from weak offline-attack resistance combined with a biased, low-entropy password generator used to encrypt key backups. At the time of reporting, any server operating under a malicious-server threat model could execute the attack.

We also uncover structural failures in the platform's key-rotation workflow. Although E2EE passwords and a master key were rotated, the group keys protecting message content were never replaced. Clients continued to accept and redistribute compromised group keys, which were then reused to encrypt new messages and decrypt past ones. A single key recovery therefore enabled expanding and persistent compromise across group communication.

Manual analysis further revealed integrity failures, including ciphertext forgery made possible by unauthenticated AES-CBC encryption.

Beyond the technical flaws, we also reconstruct how this fragile design emerged by examining public development discussions and historical commits. This OSINT analysis explains why several fundamental E2EE principles were never integrated and how long-term structural risks accumulated.

The most severe vulnerabilities, including key recovery and broken key rotation, were fixed within six months of disclosure, and remaining integrity issues were patched after extended coordination. Attendees will learn how to analyze real-world E2EE systems, detect specification-implementation gaps, and replace password-based architectures with modern best practices.

Hayato Kimura | Researcher, National Institute of Information and Communications Technology & The University of Osaka
Ryoma Ito | Senior Researcher, National Institute of Information and Communications Technology
Kazuhiko Minematsu | Research Fellow, NEC Corporation
Takanori Isobe | Professor, The University of Osaka

https://blackhat.com/asia-26/briefings/schedule/?#payload-compromised-full-key-recovery-in-rocketchat-e2ee-50105
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
111 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 45%
🟡 In Evaluierung 20%
🟢 Keine Auswirkung 16%
Spannende Innovation 19%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients
1 Quelle
Job hunt
1 Quelle
Exploits and vulnerabilities in Q2 2026