News: 1664400174

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Matrix chat encryption sunk by five now-patched holes

(2022/09/28)


Four security researchers have identified five cryptographic vulnerabilities in code libraries that can be exploited to undermine the Matrix federated communication protocol and its client software. This includes impersonating users and sending messages as them.

The researchers – Martin Albrecht (University of London), Sofía Celi (Brave Software), Benjamin Dowling (University of Sheffield) and Daniel Jones (University of London) – described their findings in a pre-print paper titled " [1]Practically-exploitable Cryptographic Vulnerabilities in Matrix " [PDF].

"Our perspective is that these attacks together show a rich attack surface in Matrix from both a protocol and implementation perspective," Benjamin Dowling, a lecturer in cybersecurity, told The Register .

Formally modeling the protocol and analyzing the security of the protocol design is an important step in catching and thus preventing attacks of this nature

"While Matrix has performed security audits of the various existing implementations, they [2]sometimes fail to catch attacks that are present due to protocol flaws. Formally modeling the protocol and analyzing the security of the protocol design is an important step in catching and thus preventing attacks of this nature."

Matrix [3]bills itself as an open standard for real-time, distributed communications with strong end-to-end encryption, user verification, and other cryptographic protection mechanisms. If you're into crypto-system design, the above PDF will be a real deep-dive treat.

[4]

The attacks – two critical and three lower priority – target the Matrix standard as implemented in the matrix-react-sdk, matrix-js-sdk, and matrix-android-sdk2 libraries, and they affect client software that incorporates such code, like Element, Beeper, Cinny, SchildiChat, Circuli, and Synod.im.

[5]

[6]

On Wednesday, The Matrix.org Foundation, which manages the decentralized communication protocol, [7]issued an advisory describing the flaws as vulnerabilities in Matrix's end-to-end encryption, and directed users of those aforementioned apps and libraries to upgrade them.

"These have now been fixed, and we have not seen evidence of them being exploited in the wild," the Matrix.org foundation said. "All of the critical vulnerabilities require cooperation from a malicious homeserver to be exploited."

[8]

The two critical bugs are identified as "Key/Device Identifier Confusion in SAS Verification" (CVE-2022-39250) and "Trusted Impersonation" (CVE: CVE-2022-39251).

The former refers to a matrix-js-sdk bug (not in the iOS or Android SDKs) that confuses device IDs with cross-signing keys, which could allow malicious server admins to impersonate target users. The latter refers to a protocol-confusion bug in matrix-js-sdk (and derived SDKs) that could allow attackers to spoof historical messages from other users. The "Trusted Impersonation" bug is also tracked as CVE-2022-39255 (matrix-ios-sdk) and CVE-2022-39248 (matrix-android-sdk2).

[9]How a glitch in the Matrix led to apps potentially exposing encrypted chats

[10]Better late than never: Microsoft rolls out a public preview of E2EE in Teams calls

[11]Early Skype developer Jaan Tallinn splashes cash in latest funding for Matrix-based instant messenger Element

[12]Slack has entered the Matrix: Element builds a bridge to realm of encrypted, decentralised comms

A variant of the "Trusted Impersonation" attack, tracked under the same CVE, is referred to as "Malicious key backup." It's a scenario in which a malicious homeserver admin could add a malicious key backup to the user's account to exfiltrate message keys.

The lower priority vulnerabilities include: "Semi-trusted Impersonation," "Homeserver Control of Room Membership," and "IND-CCA break."

With the impersonation bug, the matrix-js-sdk (and derived SDKs) accepts keys forwarded by other users that have not been requested. This allows malicious admins to impersonate other users, though clients like Element will present a warning: "The authenticity of this encrypted message can't be guaranteed."

[13]

The bug has been designated moderate severity under the identifiers: CVE-2022-39249 (matrix-js-sdk), CVE-2022-39257 (matrix-ios-sdk), and CVE-2022-39246 (matrix-android-sdk2).

Trouble at home

The "Homeserver" bug allows a malicious homeserver to issue invites to server-controlled users or add server-controlled devices to user accounts. There are warnings to avoid this but Matrix.org says it intends to improve the behavior with fixes scheduled to land in the next few months.

And the "IND-CCA break" attack could allow "an adversary is able to decrypt a challenge ciphertext by querying encryption and decryption oracles, without requesting decryption of the challenge ciphertext directly," the paper explains. However, the researchers say this attack is only theoretical as they don't see a practical way to carry it out. Repairs are nonetheless planned.

The researchers' paper observes that Matrix relies on a "bespoke cryptographic protocol [that] has not received an in-depth treatment from the cryptographic (academic or practitioner) community."

Asked whether the flaws that have surfaced validate the advice of cryptography experts to [14]stick with proven algorithms instead of rolling your own, Dowling said:

"Given that Matrix attempts to achieve strong secure messaging in a novel setting (specifically, decentralized group messaging), it follows that introducing a new protocol design is inevitable. We would instead say that these vulnerabilities highlight the need for rigorous formal analysis during the design phase and before using new cryptographic designs in production."

"While today's fixes are not complete, these are good first steps towards ensuring that Matrix lives up to its promises of confidentiality and authentication," said Daniel Jones, a doctoral candidate at Royal Holloway, University of London, in a statement. "The longer term plans communicated to us by the Matrix developers should then provide full protection against our attacks.

"Matrix occupies a unique position within the messaging space, providing an end-to-end encrypted federated messaging platform. We hope our work inspires others to scrutinize its security to ensure that potential further issues are found-and-fixed or ruled out early. Doing so will help to strengthen the platform and ensure its long-term viability." ®

Get our [15]Tech Resources



[1] https://nebuchadnezzar-megolm.github.io/static/paper.pdf

[2] https://www.theregister.com/2021/09/13/matrix_foundation_implementation_bug/

[3] https://matrix.org/docs/guides/introduction

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YzTD@Fkd26xzHKpZzt99FAAAAAA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YzTD@Fkd26xzHKpZzt99FAAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YzTD@Fkd26xzHKpZzt99FAAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://matrix.org/blog/2022/09/28/upgrade-now-to-address-encryption-vulns-in-matrix-sdks-and-clients

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YzTD@Fkd26xzHKpZzt99FAAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2021/09/13/matrix_foundation_implementation_bug/

[10] https://www.theregister.com/2021/10/22/e2ee_teams_microsoft/

[11] https://www.theregister.com/2021/07/27/element_seriesb_thirty_million_pounds_funding/

[12] https://www.theregister.com/2021/01/20/matrix_slack/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YzTD@Fkd26xzHKpZzt99FAAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.schneier.com/crypto-gram/archives/1998/1015.html#cipherdesign

[15] https://whitepapers.theregister.com/



Some more clarity

Chubango

From [1]the post that's linked haflway through the article:

>Clients with other encryption implementations (including Hydrogen, ElementX, Nheko, FluffyChat, Syphon, Timmy, Gomuks and Pantalaimon) are not affected; this is not a protocol bug.

>Meanwhile, we are taking extreme measures to avoid future E2EE vulnerabilities. You will notice that matrix-rust-sdk, hydrogen-sdk and other 2nd and 3rd generation SDKs were not affected by the bugs at the root cause of the critical issues here. This is precisely why we have been working on replacing the first generation SDKs with a clean, carefully written Rust implementation in the form of matrix-rust-sdk, complete with an ongoing independent public audit.

Just think it's worth pointing out clearly as the article mixes past problems and comments from the researchers in such a way that it seems to imply that the protocol itself is to blame rather than the implementation in these older libraries used by some of the clients.

[1] https://matrix.org/blog/2022/09/28/upgrade-now-to-address-encryption-vulns-in-matrix-sdks-and-clients

"Does it worry you that you don't talk any kind of sense? "