WeChat devs introduced security flaws when they modded TLS, say researchers
ID: 93e558c9-45ab-58cc-a8de-b2a1b4f6d180
STIX ID: report--93e558c9-45ab-58cc-a8de-b2a1b4f6d180
Feed Name: The Register (Security)
Citizen Lab analyzed WeChat's custom MMTLS and its legacy AES-CBC business-layer encryption, finding implementation weaknesses — deterministic IVs, lack of forward secrecy, AES-CBC vulnerabilities and plaintext metadata leakage (user IDs, request URIs). Although these issues deviate from standard TLS and could expose metadata internally, MMTLS currently envelopes the business-layer ciphertext and researchers found no evidence of known exploitable attacks; Tencent is reportedly migrating business-layer encryption toward AES-GCM.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
