vix.ing · top · new · best · stats · spec

When Textbook RSA is Used to Protect the Privacy of Hundreds of Millions\n of Users

2018/02/09 by Jeffrey Knockel, Thomas Ristenpart, Knockel, Jeffrey +4 · 2 voices
Computer Science · #Advanced Malware Detection Techniques #Spam and Phishing Detection #Internet Traffic Analysis and Secure E-voting

paper · pdf · doi:10.48550/arxiv.1802.03367

Abstract

We evaluate Tencent's QQ Browser, a popular mobile browser in China with\nhundreds of millions of users---including 16 million overseas, with respect to\nthe threat model of a man-in-the-middle attacker with state actor capabilities.\nThis is motivated by information in the Snowden revelations suggesting that\nanother Chinese mobile browser, UC Browser, was being used to track users by\nWestern nation-state adversaries.\n Among the many issues we found in QQ Browser that are presented in this\npaper, the use of "textbook RSA"---that is, RSA implemented as shown in\ntextbooks, with no padding---is particularly interesting because it affords us\nthe opportunity to contextualize existing research in breaking textbook RSA. We\nalso present a novel attack on QQ Browser's use of textbook RSA that is\ndistinguished from previous research by its simplicity. We emphasize that\nalthough QQ Browser's cryptography and our attacks on it are very simple, the\nimpact is serious. Thus, research into how to break very poor cryptography\n(such as textbook RSA) has both pedagogical value and real-world impact.\n

Discussions

Related