Caveat Implementor! Key Recovery Attacks on MEGA
Martin R. Albrecht, Miro Haller, Lenka Mareková, Kenneth G. Paterson
摘要
MEGA is a large-scale cloud storage and communication platform that aims to provide end-to-end encryption for stored data. A recent analysis by Backendal, Haller and Paterson (IEEE S&P 2023) invalidated these security claims by presenting practical attacks against MEGA that could be mounted by the MEGA service provider. In response, the MEGA developers added lightweight sanity checks on the user RSA private keys used in MEGA, sufficient to prevent the previous attacks.
We analyse these new sanity checks and show how they themselves can be exploited to mount novel attacks on MEGA that recover a target user's RSA private key with only slightly higher attack complexity than the original attacks. We identify the presence of an ECB encryption oracle under a target user's master key in the MEGA system; this oracle provides our adversary with the ability to partially overwrite a target user's RSA private key with chosen data, a powerful capability that we use in our attacks. We then present two distinct types of attack, each type exploiting different error conditions arising in the sanity checks and in subsequent cryptographic processing during MEGA's user authentication procedure. The first type appears to be novel and exploits the manner in which the MEGA code handles modular inversion when recomputing u = q -1 mod p. The second can be viewed as a small subgroup attack (van Oorschot and Wiener, EUROCRYPT 1996, Lim and Lee, CRYPTO 1998). We prototype the attacks and show that they work in practice.
As a side contribution, we show how to improve the RSA key recovery attack of Backendal-Haller-Paterson against the unpatched version of MEGA to require only 2 logins instead of the original 512.
We conclude by discussing wider lessons about secure implementation of cryptography that our work surfaces.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- End-to-End Encrypted Cloud Storage in the Wild: A Broken EcosystemJonas Hofmann, Kien Tuong TruongCCS 2024 · 被引用 5 次
- MFKDF: Multiple Factors Knocked Down FlatMatteo Scarlata, Matilda Backendal, Miro HallerUSENIX Security 2024 · 被引用 3 次
- End-to-End Encrypted Git ServicesYa-Nan Li, Yaqing Song, Qiang Tang, Moti YungCCS 2025 · 被引用 1 次
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password ManagersMatteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. PatersonUSENIX Security 2026
- Analyzing Cryptography in Context: A Cryptography-Native Approach to Threat ModelingRan Canetti, Julie Ha, Gabriel KaptchukUSENIX Security 2026
它引用的顶会 Paper7
- SoK: Computer-Aided CryptographyManuel Barbosa, Gilles Barthe, Karthik Bhargavan, Bruno Blanchet 等S&P 2021 · 被引用 169 次
- Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdMathy Vanhoef, Eyal RonenS&P 2020 · 被引用 146 次
- Advanced Lattice Sieving on GPUs, with Tensor CoresLéo Ducas, Marc Stevens, Wessel P. J. van WoerdenEUROCRYPT 2021 · 被引用 44 次
- Four Attacks and a Proof for TelegramMartin R. Albrecht, Lenka Mareková, Kenneth G. Paterson, Igors StepanovsS&P 2022 · 被引用 40 次
- Victory by KO: Attacking OpenPGP Using Key OverwritingLara Bruseghini, Daniel Huigens, Kenneth G. PatersonCCS 2022 · 被引用 6 次
相关 Paper
- MEGA: Malleable Encryption Goes AwryMatilda Backendal, Miro Haller, Kenneth G. PatersonS&P 2023
- A Formal Treatment of End-to-End Encrypted Cloud StorageMatilda Backendal, Hannah Davis, Felix Günther, Miro Haller 等CRYPTO 2024 · 被引用 15 次
- Secure Cloud Storage: Modularization, Network Adversaries and Adaptive CorruptionsJonas Janneck, Doreen RiepelEUROCRYPT 2026
- Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2Christof Beierle, Patrick Derbez, Gregor Leander, Gaëtan Leurent 等EUROCRYPT 2021 · 被引用 22 次
- Automated Formal Analysis of Signal's Double Ratchet: Attacks, Fixes and Security ProofsVincent Cheval, Charlie Jacomme, Jessica RichardsS&P 2026 · 被引用 3 次
