Injection Attacks Against End-to-End Encrypted Applications

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Fábrega, Andrés, Pérez, Carolina Ortega, Namavari, Armin, Nassi, Ben, Agarwal, Rachit, Ristenpart, Thomas
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866929591185047552
author Fábrega, Andrés
Pérez, Carolina Ortega
Namavari, Armin
Nassi, Ben
Agarwal, Rachit
Ristenpart, Thomas
author_facet Fábrega, Andrés
Pérez, Carolina Ortega
Namavari, Armin
Nassi, Ben
Agarwal, Rachit
Ristenpart, Thomas
contents We explore an emerging threat model for end-to-end (E2E) encrypted applications: an adversary sends chosen messages to a target client, thereby "injecting" adversarial content into the application state. Such state is subsequently encrypted and synchronized to an adversarially-visible storage. By observing the lengths of the resulting cloud-stored ciphertexts, the attacker backs out confidential information. We investigate this injection threat model in the context of state-of-the-art encrypted messaging applications that support E2E encrypted backups. We show proof-of-concept attacks that can recover information about E2E encrypted messages or attachments sent via WhatsApp, assuming the ability to compromise the target user's Google or Apple account (which gives access to encrypted backups). We also show weaknesses in Signal's encrypted backup design that would allow injection attacks to infer metadata including a target user's number of contacts and conversations, should the adversary somehow obtain access to the user's encrypted Signal backup. While we do not believe our results should be of immediate concern for users of these messaging applications, our results do suggest that more work is needed to build tools that enjoy strong E2E security guarantees.
format Preprint
id arxiv_https___arxiv_org_abs_2411_09228
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Injection Attacks Against End-to-End Encrypted Applications
Fábrega, Andrés
Pérez, Carolina Ortega
Namavari, Armin
Nassi, Ben
Agarwal, Rachit
Ristenpart, Thomas
Cryptography and Security
We explore an emerging threat model for end-to-end (E2E) encrypted applications: an adversary sends chosen messages to a target client, thereby "injecting" adversarial content into the application state. Such state is subsequently encrypted and synchronized to an adversarially-visible storage. By observing the lengths of the resulting cloud-stored ciphertexts, the attacker backs out confidential information. We investigate this injection threat model in the context of state-of-the-art encrypted messaging applications that support E2E encrypted backups. We show proof-of-concept attacks that can recover information about E2E encrypted messages or attachments sent via WhatsApp, assuming the ability to compromise the target user's Google or Apple account (which gives access to encrypted backups). We also show weaknesses in Signal's encrypted backup design that would allow injection attacks to infer metadata including a target user's number of contacts and conversations, should the adversary somehow obtain access to the user's encrypted Signal backup. While we do not believe our results should be of immediate concern for users of these messaging applications, our results do suggest that more work is needed to build tools that enjoy strong E2E security guarantees.
title Injection Attacks Against End-to-End Encrypted Applications
topic Cryptography and Security
url https://arxiv.org/abs/2411.09228