Email us! Subscribe to Liquidmatrix!

Cryptanalytic Attack In ScatterChat

SUMMARY

ScatterChat (http://www.scatterchat.com/) is an instant messaging project
that aims to provide encryption and anonymity support with Tor to
non-technical users such as human rights activists and political
dissidents.

Steven Murdoch, a security researcher with the University of Cambridge,
discovered a theoretical weakness in ScatterChat’s cryptographic module.
He found that an eavesdropper might locate patterns in a private
communications channel if extraordinarily large amounts of messages were
exchanged in a single conversation.

Note that this does not allow an eavesdropper to decrypt messages, nor
determine a user’s identity if anonymity is used.

The practical impact of this vulnerability is very low.

This will be cleared up in version 2.0 of Scatter Chat.

Article Link

Tags: , , , ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • ScatterChat Released By Hacktivismo
  • Exploit Goodness and MS06-040
  • Spamhaus Fends Off DDoS Attack
  • Schneier On Choosing Secure Passwords
  • Safari & IE Attack Code Released
  • Leave a Comment