Security researcher Soatok discovered multiple cryptographic vulnerabilities in Matrix's Rust library vodozemac, including a critical flaw where the Olm Diffie-Hellman implementation accepts all-zero public keys (the identity element), leading to predictable shared secrets. Additional issues include silent downgrades from V2 to

20m read timeFrom soatok.blog
Post cover image
Table of contents
ContentsDisclosure TimelineCryptographic Issues in VodozemacWhat’s the Impact?TakeawaysClosing Thoughts

Sort: