Skip Navigation

Security Issues in Matrix’s Olm Library (Including ongoing discussion)

soatok.blog Security Issues in Matrix’s Olm Library - Dhole Moments

I don’t consider myself exceptional in any regard, but I stumbled upon a few cryptography vulnerabilities in Matrix’s Olm library with so little effort that it was nearly accidental. It…

Security Issues in Matrix’s Olm Library - Dhole Moments

I'm reposting the article with the developing discussions around it as it probably deserves more reach. Devs are 50% "it's impossible to do anyways, sensationalism it's FUD", the other 50% is in disarray and being wtf. I'm not a cryptographer though

More discussion here, where Nheko devs refuse to update to Vodozemac: https://github.com/Nheko-Reborn/nheko/issues/1786

Others discussions: https://github.com/quotient-im/libQuotient/issues/780

https://github.com/mautrix/go/issues/262

https://github.com/NixOS/nixpkgs/pull/334638

https://github.com/krille-chan/fluffychat/issues/1258

https://github.com/NixOS/nixpkgs/pull/334638/commits/e4767b4727589567da29a90a71947c2bdbe43988

OP's old gist about Matrix: https://web.archive.org/web/20240606031827/https://gist.github.com/soatok/8aef6f67fec9c702f510ee24d19ef92b

Matrix developer reply: https://news.ycombinator.com/item?id=41249371

From what I understand, for now, Vodozemac, the new Rust implementation, is unusable in other languages than Rust because its bindings are broken. FluffyChat developers seem to be working on fixing them, though.

I think what's more worrying than the exploits is the attitude of the client developers, and the Matrix developer that replied.

1

You're viewing a single thread.

1 comments