Swiss Army's Threema messaging app was full of holes – at least seven
- Reference: 1673424066
- News link: https://www.theregister.co.uk/2023/01/11/swiss_army_threema_bugs/
- Source link:
The university's applied cryptography group this week published [1]research [PDF] detailing seven vulnerabilities in Threema's home-grown cryptographic protocols. The vulnerabilities, if exploited, could have allowed miscreants to clone accounts and read their messages, as well as steal private keys and contacts and even manufacture compromising material for blackmail purposes.
While the [2]Switzerland-based app – which bills itself as a more-secure and non-US-based alternative to WhatsApp – isn't as widely used as Signal or Telegram, its data centers are located in Alpine territory. That makes it a popular messaging app for users – like the Swiss army – who want to avoid potential snooping from overseas governments. It boasts more than ten million users and 7,000 on-premise customers – including German chancellor Olaf Scholz.
[3]
Threema downplayed the bugs in a [4]blog post about the research. The vulnerabilities were found in a protocol that Threema no longer uses, and while the bugs may be "interesting from a theoretical standpoint, none of them ever had any considerable real-world impact," according to the post.
[5]
[6]
Here's more of the Swiss company's statement:
Last year, a student at the Department of Computer Science at ETH Zurich wrote his master's thesis on Threema's communication protocol. The university has now published his work as a paper/preprint. However, the paper is based on an old protocol that is no longer in use. The presented findings do not apply to Threema's current communication protocol "Ibex" or have already been addressed. None of them ever had any considerable real-world impact."
The three researchers – computer science professor Kenneth Paterson and PhD students Matteo Scarlata and Kien Tuong Truong – noted on a [7]website about the Threema security flaws that they originally disclosed their finding to the company in October 2022, and later agreed on a January 9 public disclosure date.
Threema released its Ibex protocol in late November "to further mitigate our attacks," and the researchers noted they have not audited this new protocol, which was released after their investigation. They do, however, "believe that all of the vulnerabilities we discovered have been mitigated by Threema's recent patches," the researchers wrote.
[8]Mobile networks really hate Apple's Private Relay: Some folks find iOS privacy feature blocked on their iPhones
[9]Egad, did Apple do something right? End-to-end encryption for (most) iCloud services
[10]What's up with WhatsApp? Messaging platform suffers outage in the UK
[11]Meta, Twitter, Apple, Google urged to up encryption game in post-Roe America
In an email to The Register , Paterson noted that the old protocol "was only updated to the 'new' version because of our research."
Threema's statement "is extremely misleading," he added. "It's very disappointing that they portrayed the current situation in this highly misleading way."
While the researchers concede these specific bugs no longer pose a threat to Threema customers, their discovery still highlights the difficulty in assessing "security claims made by developers of applications that rely on bespoke cryptographic protocols."
[12]
"Ideally, any application using novel cryptographic protocols should come with its own formal security analyses (in the form of security proofs) in order to provide strong security assurances," they added. "Such an analysis can help to reduce uncertainty about whether further serious cryptographic vulnerabilities still exist in Threema." ®
Get our [13]Tech Resources
[1] https://breakingthe3ma.app/files/Threema-PST22.pdf
[2] https://www.theregister.com/2022/01/11/in_brief_security/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y76WzOtm4@qu2G8CFWWLEgAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y76WzOtm4@qu2G8CFWWLEgAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y76WzOtm4@qu2G8CFWWLEgAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://breakingthe3ma.app/
[8] https://www.theregister.com/2022/01/11/in_brief_security/
[9] https://www.theregister.com/2022/12/08/apple_encryption_icloud/
[10] https://www.theregister.com/2022/10/25/whatsapp_down_in_uk/
[11] https://www.theregister.com/2022/09/20/encryption_abortion_data/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y76WzOtm4@qu2G8CFWWLEgAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
Re: "infested with bugs – possibly for a long time"
A lot of them don't care that much as long as the servers are still in Switzerland, like many of their bank accounts.
Re: "infested with bugs – possibly for a long time"
It's not secure until a proper security research firm has confirmed that it's secure.
The question is who do you trust not to sell the bugs to dodgy characters like US Intelligence instead? This wasn't a "firm", btw, it was a Swiss University in Zürich.
That said, I hope this will also prompt 3rd party reviews of Telegram and Signal - might as well have a look at the whole set..
serious, serious bugs
Yes, the serious bugs they found require access to the servers ("In the “compromised Threema” threat model we consider
attacks by an adversary who has gained access to Threema servers")
or an unlocked phone, an unlocked app and then running a full backup. (attacks 6 and 7 from the paper).
Or social engineering (2).
Yes, possible.
If you hand someone your unlocked smartphone they can clone your account. That's not very surprising… What am I missing?
"infested with bugs – possibly for a long time"
I think it is time for governments and government institutions to realize that it is not because they say it's secure that it is.
Neither is it secure because whoever they contracted to do the job said it is.
And it's especially not secure simply because the contract said it had to be.
It's not secure until a proper security research firm has confirmed that it's secure.