Jump to content

New Browser Tool Claims to Reveal MEGA Users’ Master Key


NelsonG

Recommended Posts

[url="http://torrentfreak.com/images/megalogo.jpg"][img]http://torrentfreak.com/images/megalogo.jpg[/img][/url]Kim Dotcom’s Mega.co.nz launched as the ‘Privacy Company’ with a special emphasis on the security of its users’ files. The company says that due to encryption, no one can access a user’s files hosted on Mega unless the user gives his permission.

In the wake of the NSA scandal the usefulness of encryption has really come to the forefront and MEGA is now placed to release encrypted messaging and email services utilizing similar technology. However, the company’s claims also mean that it becomes a target for those seeking to point out potential weaknesses in its system.

A few hours ago a software developer called Michael Koziarski released a new tool which he claims highlights a fundamental issue with the encryption mechanism implemented by Mega.

The software, known as [url="http://nzkoz.github.io/MegaPWN/"]MEGApwn[/url], is a Javascript bookmarklet that runs in a web browser. Once a user is logged into MEGA it claims to reveal that user’s MEGA master key. Koziarski says that this proves that the master key itself is not encrypted and that anyone with access to a MEGA user’s computer can access it.

However, this is not the most controversial claim. Koziarski says that MEGA itself is able to grab a key and use it to access a user’s files.

“Your web browser trusts whatever it receives from MEGA, which means they can grab your master key whenever you visit their site and then use it to decrypt and read your files. You’d never know,” Koziarski explains.

[img]http://torrentfreak.com/images/megaPWN.jpg[/img]

The dev, who maintains several open source projects, says that if MEGA was issued with a subpoena it could be forced to obtain a user’s master key and be forbidden by law to reveal anything about it. He also claims that ANY installed browser extension could also access a user’s master key.

The revelations provoked an exchange with MEGA programmer [url="https://twitter.com/bramosnl/status/374669888691793920"]Bram Van der Kolk[/url], who questioned how MEGA would stop anyone gaining access to a user’s computer.

“You seriously want MEGA to protect users against this?” he said.

“No, I want users to understand just how easily you could read all their files if you wanted to,” Koziarski responded.

“You mean how easily the user himself can read his own files. How exactly can an external attacker take advantage of this?” der Kolk questioned.

“So you agree MEGA is only secure against external attackers, that you can read my files if you wanted to?” Koziarski fired back.

“Are you seriously suggesting that we will serve trojaned JavaScript? Install one of our browser extensions and turn off auto-updates,” der Kolk countered.

To try and get a clearer idea of how serious (or not) this issue is, TorrentFreak contacted both MEGA and Koziarski for comment on the new tool. We are yet to receive a response but in the meantime the latter is suggesting that while any site uses Javascript for security, the highlighted problem cannot be overcome.

“Does this code hack or break into MEGA? No, it simply demonstrates one of the many serious and insoluble problems you face when doing cryptography in Javascript web applications. There are many other problems like this which is why numerous respected cryptographers have warned against doing this for years,” he concludes.

Source: [url="http://torrentfreak.com/new-browser-tool-claims-to-reveal-mega-user-master-key-130903/"]New Browser Tool Claims to Reveal MEGA Users’ Master Key[/url]

[url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=azPpJ4LdcNc:QipBxLPPWNM:yIl2AUoC8zA"][img]http://feeds.feedburner.com/~ff/Torrentfreak?d=yIl2AUoC8zA[/img]</img>[/url] [url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=azPpJ4LdcNc:QipBxLPPWNM:D7DqB2pKExk"][img]http://feeds.feedburner.com/~ff/Torrentfreak?i=azPpJ4LdcNc:QipBxLPPWNM:D7DqB2pKExk[/img]</img>[/url][img]http://feeds.feedburner.com/~r/Torrentfreak/~4/azPpJ4LdcNc[/img]

[url=http://feed.torrentfreak.com/~r/Torrentfreak/~3/azPpJ4LdcNc/]View the full article[/url]

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...