000@reddthat.com to Technology@lemmy.worldEnglish · 22 hours agoDon’t Use Session (Signal Fork).soatok.blogexternal-linkmessage-square8fedilinkarrow-up114arrow-down11cross-posted to: privacyguides@lemmy.onelobsters@lemmy.bestiver.seprivacy@lemmy.mlprivacy@lemmy.mlprivacy@lemmy.worldtech@pawb.social
arrow-up113arrow-down1external-linkDon’t Use Session (Signal Fork).soatok.blog000@reddthat.com to Technology@lemmy.worldEnglish · 22 hours agomessage-square8fedilinkcross-posted to: privacyguides@lemmy.onelobsters@lemmy.bestiver.seprivacy@lemmy.mlprivacy@lemmy.mlprivacy@lemmy.worldtech@pawb.social
minus-squarevollkorntomate@infosec.publinkfedilinkEnglisharrow-up2·18 hours ago […] it uses the X25519 public key… as a symmetric key, for AES-GCM. […] anyone that knows the public key can decrypt it. Ouch.
Ouch.