{"id":19408,"date":"2022-06-22T08:10:03","date_gmt":"2022-06-22T16:10:03","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/06\/22\/news-13141\/"},"modified":"2022-06-22T08:10:03","modified_gmt":"2022-06-22T16:10:03","slug":"news-13141","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/06\/22\/news-13141\/","title":{"rendered":"MEGA claims it can&#8217;t decrypt your files. But someone&#8217;s managed to&#8230;"},"content":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Wed, 22 Jun 2022 15:52:41 +0000<\/strong><\/p>\n<p>MEGA, the cloud storage provider and file hosting service, is <a href=\"https:\/\/blog.mega.io\/how-to-prevent-credential-stuffing\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">very proud<\/a> of its end-to-end <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2013\/09\/encryption-types-of-secure-communication-and-storage\/\">encryption<\/a>. It says it <a href=\"https:\/\/mega.io\/security\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">couldn&#8217;t decrypt your stored files<\/a>, even if it wanted to.<\/p>\n<p>\u201cAll your data on MEGA is encrypted with a key derived from your password; in other words, your password is your main encryption key. MEGA does not have access to your password or your data. Using a strong and unique password will ensure that your data is protected from being hacked and gives you total confidence that your information will remain just that \u2013 yours.\u201d<\/p>\n<p>But there&#8217;s a problem. A Swiss team of researchers has just proved those claims <a href=\"https:\/\/mega-awry.io\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">wrong<\/a>. <\/p>\n<p>And that&#8217;s not all. The research went one step further, finding that an attacker could insert malicious files into the storage, passing all authenticity checks of the client.<\/p>\n<h2>Cryptography flaws<\/h2>\n<p>Researchers at the Department of Computer Science of the ETH Zurich in Zurich, Switzerland reviewed the security of MEGA and found significant issues in how it uses cryptography.<\/p>\n<p>These findings could lead to devastating attacks on the confidentiality and integrity of user data in the MEGA cloud.<\/p>\n<h2>Key hierarchy<\/h2>\n<p>The MEGA client derives an authentication key and an encryption key from the password. The authentication key identifies users to MEGA. The encryption key encrypts a randomly generated master key, which in turn encrypts other key material of the user. Every account has a set of asymmetric keys: An RSA key pair for sharing data, a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Curve25519\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Curve25519<\/a> key pair for exchanging chat keys for MEGA\u2019s chat functionality, and an <a href=\"https:\/\/en.wikipedia.org\/wiki\/EdDSA\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Ed25519<\/a> key pair for signing the other keys. Furthermore, the client generates a new key for every file or folder (collectively referred to as nodes) uploaded by the user.<\/p>\n<p>Long story short, all the keys are derived in one way or another from the password. And all the keys get stored on MEGA\u2019s servers to support access from multiple devices.<\/p>\n<h2>Ciphertext<\/h2>\n<p>Ciphertext is encrypted text transformed from plaintext using an encryption algorithm. The researchers built two attacks based on the lack of integrity protection of ciphertexts containing keys, and two further attacks to breach the integrity of file ciphertexts and allow a malicious service provider to insert chosen files into a user&#8217;s cloud storage.<\/p>\n<h2>Attacks<\/h2>\n<p>Due to the flawed integrity protection, a malicious service provider can recover a user\u2019s private RSA share key (used to share file and folder keys) over 512 login attempts. The number is 512 because of the RSA-CRT implementation used by MEGA clients to build an oracle that leaks one bit of information per login attempt about a factor of the RSA modulus.<\/p>\n<p>As a result the malicious service provider can recover any plaintext encrypted with AES-ECB under a user\u2019s master key. This includes all node keys used for encrypting files and folders. As a consequence, the confidentiality of all user data protected by these keys, such as files and chat messages, is lost.<\/p>\n<p>Based on the first two attacks, a malicious service provider can construct an encrypted file. The user cannot demonstrate that they didn&#8217;t upload the forged data because the files and keys are indistinguishable from genuinely uploaded ones. It needs no further explanation that introducing a malicious file in such an attack could further compromise not only the user\u2019s system, but also for those the user has shared their files or folders with.<\/p>\n<h2>MEGA\u2019s response<\/h2>\n<p>MEGA acknowledged the issue on March 24, 2022, and <a href=\"https:\/\/blog.mega.io\/mega-security-update\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released patches on June 21, 2022<\/a>, awarding the researchers a bug bounty. But MEGA&#8217;s fix differs greatly from what the researchers proposed, patching only for the first attack alone since the other attacks rely on the first one.<\/p>\n<p>Since that does not fix the key reuse issue, lack of integrity checks, and other systemic problems the researchers identified, this remains a source of concern for them.<\/p>\n<p>As a regular MEGA user there is no reason to worry about these flaws, especially if you haven\u2019t logged in more than 512 times. An attacker would need to have control over MEGA\u2019s API servers or TLS connections without being noticed to perform any of these attacks.<\/p>\n<p>Anyone interested in more technical details, can read the <a href=\"https:\/\/mega-awry.io\/pdf\/mega-malleable-encryption-goes-awry.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">researcher\u2019s paper<\/a>.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/reports\/2022\/06\/mega-claims-it-cant-decrypt-your-files-but-someones-managed-to\/\">MEGA claims it can&#8217;t decrypt your files. But someone&#8217;s managed to&#8230;<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/reports\/2022\/06\/mega-claims-it-cant-decrypt-your-files-but-someones-managed-to\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Wed, 22 Jun 2022 15:52:41 +0000<\/strong><\/p>\n<p>Swiss researchers debunked MEGA&#8217;s claims that anyone that would be able to take over MEGA&#8217;s infrastructure would still not have access to your information and files.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/reports\/2022\/06\/mega-claims-it-cant-decrypt-your-files-but-someones-managed-to\/\">MEGA claims it can&#8217;t decrypt your files. But someone&#8217;s managed to&#8230;<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[26655,26656,26657,10439,20724,1804],"class_list":["post-19408","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-ciphertext","tag-curve25519","tag-ed25519","tag-encryption","tag-mega","tag-reports"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19408","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19408"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19408\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19408"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19408"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19408"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}